SY0-701 exam dumps

SY0-701 practice question 363 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 363

Single answerFactors: Something you know , Something you have , Something you are , Somewhere you are

A financial services company allows employees to access its trading platform remotely. After several account takeover attempts using stolen passwords, the security team wants to strengthen authentication without issuing hardware tokens to every employee. The team decides that logins should require the user's password and should only be allowed when the user is physically present at an approved office location. Which authentication combination best meets this requirement?

  1. A

    Something you know and somewhere you are

  2. B

    Something you know and something you are

  3. C

    Something you have and something you are

  4. D

    Somewhere you are and something you have

Show answer and explanation

Correct answer: A

Explanation

The best answer is 'something you know and somewhere you are' because it aligns exactly with the scenario's two stated requirements: continue using passwords and restrict access to approved physical locations. In Security+ terminology, authentication factors are commonly grouped as something you know (for example, a password or PIN), something you have (for example, a token or smart card), something you are (for example, a fingerprint), and somewhere you are (for example, geolocation, network location, or presence at a trusted site). This question tests the ability to distinguish factor types and apply them to a business constraint. Best practices from NIST guidance on digital identity, including SP 800-63, recognize multiple authenticator categories and support using contextual or location-based restrictions as part of access control policy, even though location is often considered supplemental context in implementation. In practice, organizations may enforce 'somewhere you are' through geofencing, source network restrictions, conditional access, or requiring connection from a trusted corporate location.

  • A. Correct.

    Correct. A password is a classic 'something you know' factor, and restricting access based on an approved office location uses the 'somewhere you are' factor, typically enforced through geofencing, GPS validation, network location, or trusted site controls. This directly matches the stated requirement: keep passwords and permit access only from approved physical locations without distributing hardware tokens.

  • B. Incorrect.

    Incorrect. 'Something you are' refers to a biometric factor such as a fingerprint, facial recognition, or iris scan. While this could strengthen authentication, it does not satisfy the requirement that access be limited based on the user's physical location. A candidate might choose this because biometrics are a common MFA factor, but the scenario specifically calls for location-based control.

  • C. Incorrect.

    Incorrect. This combination uses possession and biometric factors, such as a smart card plus fingerprint. It could provide strong MFA, but it conflicts with the requirement to avoid issuing hardware tokens to every employee. It also does not address the need to allow logins only from approved office locations.

  • D. Incorrect.

    Incorrect. This option includes location and possession, such as being at an approved site and using a badge, phone, or token. However, the scenario explicitly says the team wants logins to require the user's password, which is a knowledge factor. In addition, the company does not want to issue hardware tokens broadly, making this a poor fit.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam