SY0-701 exam dumps

SY0-701 practice question 362 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 362

Single answerFactors: Something you know , Something you have , Something you are , Somewhere you are

A financial services company is tightening access to its wire-transfer system after a phishing incident exposed several employee passwords. The security team wants remote employees to use true multifactor authentication that remains effective even if a password is stolen. Which solution BEST meets this requirement?

  1. A

    Require employees to enter a password and answer a security question before accessing the system

  2. B

    Require employees to enter a password and approve a login with a hardware security token that generates a one-time code

  3. C

    Require employees to scan a fingerprint twice using the laptop sensor before accessing the system

  4. D

    Allow access only from the corporate office IP range and require a password for login

Show answer and explanation

Correct answer: B

Explanation

The best answer is the combination of a password and a hardware token because it uses two distinct authentication factors: something you know and something you have. Security+ expects candidates to distinguish between true multifactor authentication and multiple prompts from the same factor category. For example, a password plus security question is not MFA because both are knowledge factors, and repeating a fingerprint scan is still only one biometric factor. Location can be used as an authentication factor in some designs, but the scenario specifically requires remote access, so limiting access to the corporate office IP range is operationally unsuitable. Best practices reflected in NIST guidance, such as NIST SP 800-63 Digital Identity Guidelines, emphasize the use of different authenticator types and stronger phishing-resistant methods where feasible.

  • A. Incorrect.

    Incorrect. A password and a security question are both examples of the same factor category: something you know. Using two credentials from the same factor does not create multifactor authentication. This is a common misconception because it feels like two steps, but it is still single-factor from an authentication-factor perspective.

  • B. Correct.

    Correct. A password is something you know, and a hardware token that generates a one-time code is something you have. Combining two different factor types creates true multifactor authentication. This approach also helps reduce the impact of a stolen password because an attacker would still need possession of the token.

  • C. Incorrect.

    Incorrect. A fingerprint is something you are. Scanning the same biometric twice does not add another factor; it is still a single factor used repeatedly. Candidates sometimes confuse multiple prompts with multiple factors, but Security+ distinguishes factors by category, not by the number of times they are presented.

  • D. Incorrect.

    Incorrect. Restricting access by corporate office IP range uses location, or somewhere you are, and the password is something you know. While this can be considered two different factor types in some contexts, it does not meet the stated requirement for remote employees because remote workers would not normally originate from the corporate office IP range. It also conflicts with the business need to support remote access.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam