nerdexam
CompTIA

220-1102 · Question #532

A company is creating an access control system that uses something you have and something you are. Which of the following will be required for user authentication? (Choose two.)

The correct answer is C. Biometric scanner D. Smartcard reader. For an access control system requiring 'something you have' and 'something you are' for authentication, a smartcard reader and a biometric scanner are the necessary components. These two factors combine distinct authentication methods to enhance security.

Security

Question

A company is creating an access control system that uses something you have and something you are. Which of the following will be required for user authentication? (Choose two.)

Options

  • APassword manager
  • BEncryption keys
  • CBiometric scanner
  • DSmartcard reader
  • EHost-based IDS
  • FPIN code

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    3% (1)
  • C
    86% (25)
  • E
    3% (1)

Why each option

For an access control system requiring 'something you have' and 'something you are' for authentication, a smartcard reader and a biometric scanner are the necessary components. These two factors combine distinct authentication methods to enhance security.

APassword manager

A password manager helps users store and manage passwords, which is 'something you know,' not 'something you have' or 'something you are.'

BEncryption keys

Encryption keys are used for data protection and secure communication, not typically as direct user authentication factors in the 'something you have/are' context, though they might be stored on a 'something you have' device.

CBiometric scannerCorrect

A biometric scanner represents 'something you are,' verifying identity based on unique biological characteristics like fingerprints, facial recognition, or iris scans.

DSmartcard readerCorrect

A smartcard reader is used with a smartcard, which represents 'something you have,' a physical token carried by the user containing authentication credentials.

EHost-based IDS

A host-based IDS (Intrusion Detection System) monitors a single host for malicious activity and is a security control, not an authentication factor for a user.

FPIN code

A PIN code is a form of 'something you know,' similar to a password, not 'something you have' or 'something you are.'

Concept tested: Multi-factor authentication types (something you have/are)

Source: https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-domain-services-overview#authentication

Topics

#Authentication factors#Biometrics#Smartcard authentication#Access control

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice