Courseiva
easyMultiple ChoiceObjective-mapped

CISSP Practice Question: A small business wants to implement multifactor…

A small business wants to implement multifactor authentication (MFA) for remote access to its internal network. The solution must be cost-effective and easy to deploy. Which combination is most appropriate?

⚠ Common exam trap

The trap here is that candidates may incorrectly assume that any two different authentication methods automatically constitute MFA, forgetting that MFA requires factors from at least two distinct categories (knowledge, possession, inherence), and that cost-effectiveness and ease of deployment are key constraints in this scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Password and one-time passcode sent via SMS

It combines a password (something you know) with a one-time passcode sent via SMS (something you have), satisfying the definition of multifactor authentication. SMS-based OTP is cost-effective and easy to deploy for a small business, as it requires no additional hardware or complex infrastructure, leveraging existing mobile networks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Fingerprint scanner and password

    Why it's wrong here

    Implementing fingerprint scanners across an entire small business workforce introduces significant capital expenditure for hardware and ongoing maintenance. The cost of purchasing and deploying reliable biometric readers for each user, coupled with the complexity of managing biometric templates and potential enrollment issues, makes this option financially impractical and operationally burdensome for a small business with limited IT resources.

  • Password and one-time passcode sent via SMS

    Why this is correct

    This option effectively combines 'something you know' (password) with 'something you have' (the mobile phone receiving the OTP), satisfying the criteria for multifactor authentication. SMS-based one-time passcodes are highly accessible and cost-effective, leveraging existing employee mobile devices without requiring additional hardware purchases or complex infrastructure deployment, making it an ideal, low-barrier solution for a small business.

  • Smart card and PIN

    Why it's wrong here

    Smart cards, while providing robust 'something you have' authentication when combined with a PIN ('something you know'), necessitate significant upfront investment for card readers, the smart cards themselves, and specialized software. The logistical challenges of distributing, enrolling, and managing these physical tokens and their associated infrastructure represent a substantial operational and financial burden that typically exceeds the capabilities and budget of a small business.

  • Password and security questions

    Why it's wrong here

    Security questions, despite requiring user input beyond a password, do not constitute a true second authentication factor because they are also a form of 'something you know.' The answers are often static, potentially guessable, or discoverable through social engineering, failing to provide a distinct and independent layer of security that a different factor type, like 'something you have' or 'something you are,' would offer.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.