Courseiva
Security →easyMultiple Select

FC0-U71 Security Practice Question

Which TWO of the following are examples of multi-factor authentication?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A smart card and a PIN

It combines two distinct authentication factors: something you have (the smart card) and something you know (the PIN), which is the definition of multi-factor authentication. Option C (a password and a fingerprint scan) is also correct because it pairs something you know (the password) with something you are (the fingerprint biometric), satisfying MFA's requirement for different factor categories. Option B (two different passwords) is not MFA because both are the same factor type—something you know—so it is merely multi-instance, not multi-factor. Option D (a username and a password) is not MFA because a username is an identifier, not an authentication factor, and the password alone represents a single factor. Option E (a password and a security question) is not MFA because both are knowledge-based factors (something you know), so they belong to the same factor category.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A smart card and a PIN

    Why this is correct

    Combining a smart card (something you have) with a PIN (something you know) satisfies multi-factor authentication by drawing on two distinct credential categories. This pairing meets the stem's requirement for genuine MFA, unlike methods relying on a single factor repeated or two instances of the same category.

  • ✗

    Two different passwords

    Why it's wrong here

    Two passwords both sit in the knowledge factor, so combining them satisfies only one authentication category and never constitutes MFA. This is tempting because it uses two separate credentials, but MFA requires distinct factors such as knowledge plus possession, for example a password with an authenticator app code.

  • ✓

    A password and a fingerprint scan

    Why this is correct

    Combining a password (something you know) with a fingerprint scan (something you are) satisfies multi-factor authentication by drawing on two distinct credential categories. Because the factors differ in type, compromise of the password alone cannot grant access, directly meeting the stem's requirement for genuine MFA rather than single-factor repetition.

  • ✗

    A username and a password

    Why it's wrong here

    A username identifies the account rather than authenticating it, and a password alone is single-factor knowledge authentication. This pairing is tempting because it is the most familiar login pattern, but MFA demands two different factor types, such as a password plus a hardware token or biometric.

  • ✗

    A password and a security question

    Why it's wrong here

    A security question is recalled knowledge, the same factor category as the password, so pairing them yields single-factor authentication. It is tempting because two prompts appear, but MFA requires different categories, for example a password combined with a smart card or fingerprint.

About these practice questions

Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.