easyMultiple ChoiceObjective-mapped
CISSP Practice Question: A small business wants to implement multifactor…
A small business wants to implement multifactor authentication (MFA) for remote access to its internal network. The solution must be cost-effective and easy to deploy. Which combination is most appropriate?
⚠ Common exam trap
The trap here is that candidates may incorrectly assume that any two different authentication methods automatically constitute MFA, forgetting that MFA requires factors from at least two distinct categories (knowledge, possession, inherence), and that cost-effectiveness and ease of deployment are key constraints in this scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Password and one-time passcode sent via SMS
It combines a password (something you know) with a one-time passcode sent via SMS (something you have), satisfying the definition of multifactor authentication. SMS-based OTP is cost-effective and easy to deploy for a small business, as it requires no additional hardware or complex infrastructure, leveraging existing mobile networks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fingerprint scanner and password
Why it's wrong here
Implementing fingerprint scanners across an entire small business workforce introduces significant capital expenditure for hardware and ongoing maintenance. The cost of purchasing and deploying reliable biometric readers for each user, coupled with the complexity of managing biometric templates and potential enrollment issues, makes this option financially impractical and operationally burdensome for a small business with limited IT resources.
- ✓
Password and one-time passcode sent via SMS
Why this is correct
This option effectively combines 'something you know' (password) with 'something you have' (the mobile phone receiving the OTP), satisfying the criteria for multifactor authentication. SMS-based one-time passcodes are highly accessible and cost-effective, leveraging existing employee mobile devices without requiring additional hardware purchases or complex infrastructure deployment, making it an ideal, low-barrier solution for a small business.
- ✗
Smart card and PIN
Why it's wrong here
Smart cards, while providing robust 'something you have' authentication when combined with a PIN ('something you know'), necessitate significant upfront investment for card readers, the smart cards themselves, and specialized software. The logistical challenges of distributing, enrolling, and managing these physical tokens and their associated infrastructure represent a substantial operational and financial burden that typically exceeds the capabilities and budget of a small business.
- ✗
Password and security questions
Why it's wrong here
Security questions, despite requiring user input beyond a password, do not constitute a true second authentication factor because they are also a form of 'something you know.' The answers are often static, potentially guessable, or discoverable through social engineering, failing to provide a distinct and independent layer of security that a different factor type, like 'something you have' or 'something you are,' would offer.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Components
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.