N10-009 Network Security Practice Question
A company wants to ensure that only authorized users can access the internal network by requiring both a password and a one-time code from a mobile app. This is an example of:
⚠ Common exam trap
CompTIA often tests the distinction between two-factor authentication and multifactor authentication, where candidates mistakenly think that using two different types of the same factor (e.g., two passwords) counts as 2FA, but the key is that the factors must come from different categories (knowledge, possession, inherence).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Two-factor authentication
Two-factor authentication (2FA) requires exactly two distinct authentication factors from different categories: something you know (password) and something you have (one-time code from a mobile app). This matches the scenario precisely, as the password is a knowledge factor and the mobile app-generated code is a possession factor, satisfying the definition of 2FA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Two-factor authentication
Why this is correct
Two-factor authentication (2FA) requires a user to present two distinct types of authentication factors to verify their identity. Typically, this involves something the user knows, like a password or PIN, combined with something the user possesses, such as a one-time code generated by a hardware token or sent to a mobile device. This combination significantly enhances security by making it much harder for unauthorized individuals to gain access, even if one factor is compromised, aligning with the need for a password and a code.
- ✗
Single sign-on
Why it's wrong here
Single sign-on (SSO) is an authentication scheme that allows a user to log in with a single set of credentials to multiple independent software systems. Its primary benefit is convenience and reduced credential fatigue, enabling seamless access across various applications after an initial authentication. While SSO can be configured to *use* multifactor authentication, it is not an authentication factor itself, nor does it inherently add multiple factors to a login process; it streamlines access rather than defining the number of factors.
When this WOULD be correct
An exam question might ask: 'A company wants users to authenticate once and then access multiple cloud applications without re-entering credentials. Which technology should they implement?' In that scenario, single sign-on (SSO) would be the correct answer.
- ✗
Biometric authentication
Why it's wrong here
Biometric authentication relies on unique physical or behavioral characteristics of an individual for identity verification. Examples include fingerprint scans, facial recognition, iris scans, or voice patterns, which fall under the 'something you are' category. This method is distinct from using a password (knowledge) and a one-time code (possession), as it leverages inherence rather than learned or owned credentials, making it an incorrect fit if the scenario specifically implies a password and a code.
When this WOULD be correct
A question that asks: 'A company implements fingerprint scanning to verify user identity before granting access. This is an example of what?' would make biometric authentication correct.
- ✗
Multifactor authentication with three factors
Why it's wrong here
Multifactor authentication (MFA) with three factors would necessitate the presentation of three independent categories of authentication. This typically means combining knowledge (e.g., password), possession (e.g., security token), and inherence (e.g., fingerprint or facial scan). Since the scenario describes only a password (knowledge) and a one-time code (possession), it only involves two distinct factors, not three, making this option an inaccurate description of the authentication method.
When this WOULD be correct
If the question described requiring a password, a one-time code from a mobile app, and a fingerprint scan, then it would be multifactor authentication with three factors (knowledge, possession, inherence).
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓Two-factor authenticationCorrect answer▾
Why this is correct
Two-factor authentication (2FA) requires a user to present two distinct types of authentication factors to verify their identity. Typically, this involves something the user knows, like a password or PIN, combined with something the user possesses, such as a one-time code generated by a hardware token or sent to a mobile device. This combination significantly enhances security by making it much harder for unauthorized individuals to gain access, even if one factor is compromised, aligning with the need for a password and a code.
✗Single sign-onWrong answer — click to see why▾
Why this is wrong here
Single sign-on (SSO) allows a user to log in once and access multiple systems without re-entering credentials, but it does not inherently require a one-time code from a mobile app. The question describes two distinct authentication factors (password and one-time code), which is two-factor authentication, not SSO.
★ When this WOULD be the correct answer
An exam question might ask: 'A company wants users to authenticate once and then access multiple cloud applications without re-entering credentials. Which technology should they implement?' In that scenario, single sign-on (SSO) would be the correct answer.
Why candidates choose this
Candidates may confuse SSO with the convenience of using a mobile app for authentication, or they might think that SSO always involves a second factor, when in fact SSO is about access management across systems, not about the number of authentication factors.
✗Biometric authenticationWrong answer — click to see why▾
Why this is wrong here
The question describes a password plus a one-time code from a mobile app, which are two different factors (something you know and something you have), not biometrics.
★ When this WOULD be the correct answer
A question that asks: 'A company implements fingerprint scanning to verify user identity before granting access. This is an example of what?' would make biometric authentication correct.
Why candidates choose this
Candidates may confuse the one-time code from a mobile app as a biometric factor, or mistakenly think that any authentication method involving a mobile device is biometric.
✗Multifactor authentication with three factorsWrong answer — click to see why▾
Why this is wrong here
The scenario uses only two factors (password and one-time code), so it is two-factor authentication, not three-factor. Multifactor authentication with three factors would require three distinct categories, such as password, token, and biometric.
★ When this WOULD be the correct answer
If the question described requiring a password, a one-time code from a mobile app, and a fingerprint scan, then it would be multifactor authentication with three factors (knowledge, possession, inherence).
Why candidates choose this
Candidates may confuse 'multifactor' with 'multiple factors' and think that using two factors qualifies as multifactor with three factors, misunderstanding that the number of factors must match the label.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
Courseiva writes every N10-009 question from scratch — 464 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.