Courseiva
Security →hardMultiple Choice

FC0-U71 Security Practice Question

An organization's security policy requires that users prove their identity with something they know and something they have when accessing the payroll system from outside the office. A user enters a password and then a code generated by a mobile app. Which security concept does this scenario illustrate?

⚠ Common exam trap

Watch out — candidates often confuse authentication strength with access control or federation, when the deciding detail is that two different factor categories are being presented.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multifactor authentication

Multifactor authentication combines evidence from different categories, such as knowledge, possession, and inherence. A password is something the user knows, and a code generated on an enrolled mobile app is tied to something the user has. Together they satisfy the policy requiring two distinct factor types and make stolen passwords alone insufficient to reach the payroll system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Single sign-on

    Why it's wrong here

    Single sign-on lets a user authenticate once and then access multiple systems without re-entering credentials. It reduces password fatigue and centralizes authentication, but it does not by itself require two different categories of evidence. The scenario describes a user supplying a password plus a time-based code, which is a multi-factor arrangement rather than a single authentication event granting access to many applications.

  • ✗

    Role-based access control

    Why it's wrong here

    Role-based access control assigns permissions based on a user's job role rather than on how the user proves identity. It governs what an authenticated user can do after login, not the authentication process itself. The scenario focuses on a password plus an app-generated code, which is about verifying identity, so role-based access control does not describe what is happening here.

  • ✗

    Federation

    Why it's wrong here

    Federation allows separate organizations or domains to trust each other's authentication assertions so users can access resources across boundaries with one identity. It is about trust relationships between systems, not about the number or type of credentials a user presents. The scenario involves one organization and two different evidence types, which is multifactor authentication rather than federated identity.

  • ✓

    Multifactor authentication

    Why this is correct

    Multifactor authentication requires evidence from at least two different categories: something the user knows, something the user has, or something the user is. The password represents knowledge, and the code generated by the mobile app represents possession of the enrolled device. Because the two factors come from different categories, this scenario is a textbook example of multifactor authentication protecting access to the payroll system.

About these practice questions

One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.