220-1102 exam dumps

220-1102 practice question 398 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 398

Single answerAuthentication

A company is rolling out a new remote access portal for employees who work from home. The IT manager wants to reduce the risk of unauthorized access if a user's password is exposed in a phishing attack. However, the solution must still be practical for employees using company-issued smartphones. Which authentication change would BEST meet this requirement?

  1. A

    Require users to change their passwords every 30 days

  2. B

    Implement multifactor authentication using a password and a one-time code from an authenticator app

  3. C

    Increase the minimum password length from 8 to 10 characters

  4. D

    Lock user accounts after one failed login attempt

Show answer and explanation

Correct answer: B

Explanation

The best answer is to implement multifactor authentication with an authenticator app. In A+ Core 2, candidates are expected to understand authentication factors and choose controls appropriate to the business need. In this scenario, the primary risk is credential theft through phishing. MFA mitigates that risk by requiring an additional factor, such as a time-based one-time password (TOTP) generated by an app on the employee's smartphone. This aligns with widely accepted security best practices from sources such as NIST SP 800-63, which emphasizes stronger authentication mechanisms over outdated practices like forced frequent password changes. The other options may improve security in limited ways, but they do not address the stated threat as effectively as MFA.

  • A. Incorrect.

    This is incorrect. More frequent password changes do not directly prevent account compromise when a password has already been stolen. Modern security guidance, including NIST best practices, generally favors strong passwords and monitoring over forced frequent rotation unless there is evidence of compromise.

  • B. Correct.

    This is correct. Multifactor authentication (MFA) adds a second factor beyond something the user knows. Using a password plus a one-time code from an authenticator app significantly reduces the chance that a stolen password alone can be used to access the remote portal. This is practical for users with company-issued smartphones and is a common real-world control for remote access.

  • C. Incorrect.

    This is incorrect. Increasing password length can improve password strength, but it does not address the core problem in the scenario: a password exposed through phishing can still be used by an attacker. A stronger password helps against guessing and brute-force attacks, but not against reuse of a known stolen password.

  • D. Incorrect.

    This is incorrect. Account lockout can help reduce brute-force attempts, but locking an account after a single failed login would create an unnecessary denial-of-service risk and poor user experience. It also does not solve the issue of a valid stolen password being used successfully on the first attempt.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam