CISSP Identity and Access Management Practice Question
An organization requires users to authenticate with a password and a one-time code sent to their mobile phone. This is an example of which authentication method?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Multi-factor authentication
Using two different types of factors (password - Type 1, OTP - Type 2) constitutes multi-factor authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Two-step verification
Why it's wrong here
Two-step verification (2SV) involves a second authentication step, but it does not inherently guarantee the use of a different authentication factor type. For instance, it could involve a password followed by security questions, both relying on "something you know." While often implemented with different factors, 2SV's definition is broader and doesn't strictly meet the security requirement of combining distinct factor types for enhanced assurance, which is the hallmark of true multi-factor authentication.
- ✗
Single-factor authentication
Why it's wrong here
Single-factor authentication (SFA) relies on only one category of authentication credential, such as solely a password ("something you know") or a smart card ("something you have"). This method is inherently less secure as compromise of that single factor grants full access. The question implies a need for a more robust authentication mechanism than just a password, making SFA an insufficient security control against modern threats like phishing or credential stuffing.
- ✗
Step-up authentication
Why it's wrong here
Step-up authentication is a dynamic security measure where additional authentication factors are requested only when a user attempts to access more sensitive resources or perform high-risk transactions *after* an initial login. The scenario describes a general organizational requirement for user authentication at the standard login stage, not a conditional enhancement for specific, elevated operations. Therefore, it doesn't address the baseline authentication need.
- ✓
Multi-factor authentication
Why this is correct
Multi-factor authentication (MFA) is the correct choice because it mandates the use of two or more distinct authentication factor types to verify a user's identity. These factors typically include "something you know" (e.g., password), "something you have" (e.g., token, phone), and "something you are" (e.g., fingerprint). By combining different categories, MFA significantly enhances security, making it exponentially harder for unauthorized individuals to gain access even if one factor is compromised.
Go deeper
Related to this question
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.