nerdexam
CompTIA

220-1002 · Question #14

Ann, a user, is attempting to log in to her email service form a third-party email client on her phone. When Ann enters her usual username and password, she receives an error message saying the…

The correct answer is C. Multifactor authentication. Multifactor authentication (MFA) on an email account can block third-party clients that do not natively support MFA flows, causing credential errors even after a password reset. The third-party app cannot complete the additional authentication challenge.

Mobile devices

Question

Ann, a user, is attempting to log in to her email service form a third-party email client on her phone. When Ann enters her usual username and password, she receives an error message saying the credentials are invalid. Ann then decides to reset her email password, but after the reset, the new credentials still do not work in the third-party email client. Which of the following settings or features is responsible for the problems Ann is experiencing?

Options

  • AFull device encryption
  • BAccount lock
  • CMultifactor authentication
  • DStrong password requirements

How the community answered

(25 responses)
  • A
    16% (4)
  • B
    4% (1)
  • C
    76% (19)
  • D
    4% (1)

Why each option

Multifactor authentication (MFA) on an email account can block third-party clients that do not natively support MFA flows, causing credential errors even after a password reset. The third-party app cannot complete the additional authentication challenge.

AFull device encryption

Full device encryption protects data at rest and does not affect the validity of account credentials used to authenticate to a remote email service.

BAccount lock

An account lock would prevent access, but resetting the password would unlock the account and restore access, which did not happen here.

CMultifactor authenticationCorrect

When MFA is enabled on an account, many third-party email clients cannot handle the secondary authentication challenge and report credentials as invalid. A password reset does not resolve the issue because the problem is not the password itself but the client's inability to complete the MFA prompt - typically resolved by generating an app-specific password from the provider.

DStrong password requirements

Strong password requirements would be satisfied after a password reset if the new password meets the complexity criteria, so this would not persist after the reset.

Concept tested: MFA impact on third-party email client authentication

Source: https://support.microsoft.com/en-us/account-billing/using-app-passwords-with-apps-that-don-t-support-two-step-verification-5896ed9b-4263-e681-128a-a6f2979a7944

Topics

#multifactor authentication#third-party email client#mobile email#app passwords

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice