Courseiva
Identity and Access ManagementmediumMultiple ChoiceObjective-mapped

CISSP Identity and Access Management Practice Question

An organization requires users to authenticate with a password and a one-time code sent to their mobile phone. This is an example of which authentication method?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Multi-factor authentication

Using two different types of factors (password - Type 1, OTP - Type 2) constitutes multi-factor authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Two-step verification

    Why it's wrong here

    Two-step verification (2SV) involves a second authentication step, but it does not inherently guarantee the use of a different authentication factor type. For instance, it could involve a password followed by security questions, both relying on "something you know." While often implemented with different factors, 2SV's definition is broader and doesn't strictly meet the security requirement of combining distinct factor types for enhanced assurance, which is the hallmark of true multi-factor authentication.

  • Single-factor authentication

    Why it's wrong here

    Single-factor authentication (SFA) relies on only one category of authentication credential, such as solely a password ("something you know") or a smart card ("something you have"). This method is inherently less secure as compromise of that single factor grants full access. The question implies a need for a more robust authentication mechanism than just a password, making SFA an insufficient security control against modern threats like phishing or credential stuffing.

  • Step-up authentication

    Why it's wrong here

    Step-up authentication is a dynamic security measure where additional authentication factors are requested only when a user attempts to access more sensitive resources or perform high-risk transactions *after* an initial login. The scenario describes a general organizational requirement for user authentication at the standard login stage, not a conditional enhancement for specific, elevated operations. Therefore, it doesn't address the baseline authentication need.

  • Multi-factor authentication

    Why this is correct

    Multi-factor authentication (MFA) is the correct choice because it mandates the use of two or more distinct authentication factor types to verify a user's identity. These factors typically include "something you know" (e.g., password), "something you have" (e.g., token, phone), and "something you are" (e.g., fingerprint). By combining different categories, MFA significantly enhances security, making it exponentially harder for unauthorized individuals to gain access even if one factor is compromised.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.