nerdexam
CompTIA

SY0-501 · Question #196

An employer requires that employees use a key-generating app on their smartphones to log into corporate applications. In terms of authentication of an individual, this type of access policy is BEST de

The correct answer is A. Something you have.. The access policy described involves using a key-generating app on a smartphone, which is a prime example of the 'something you have' authentication factor, as it relies on the possession of a specific device.

Submitted by the_admin· Mar 4, 2026General security concepts

Question

An employer requires that employees use a key-generating app on their smartphones to log into corporate applications. In terms of authentication of an individual, this type of access policy is BEST defined as:

Options

  • ASomething you have.
  • BSomething you know.
  • CSomething you do.
  • DSomething you are.

How the community answered

(38 responses)
  • A
    79% (30)
  • B
    3% (1)
  • C
    5% (2)
  • D
    13% (5)

Why each option

The access policy described involves using a key-generating app on a smartphone, which is a prime example of the 'something you have' authentication factor, as it relies on the possession of a specific device.

ASomething you have.Correct

This option is correct because a key-generating app on a smartphone functions as a security token that the user physically possesses. This 'something you have' factor in multi-factor authentication (MFA) relies on the user demonstrating ownership of a specific item, such as a physical token, smart card, or in this case, a smartphone running an authenticator app that generates time-based one-time passwords (TOTP) or receives push notifications.

BSomething you know.

This option is incorrect because 'something you know' refers to knowledge-based factors like passwords, PINs, or security questions, which are not what a key-generating app provides.

CSomething you do.

This option is incorrect because 'something you do' refers to behavioral characteristics or patterns like typing cadence or specific gestures, not the use of a key-generating application.

DSomething you are.

This option is incorrect because 'something you are' refers to inherent biometric attributes such as fingerprints, facial recognition, or iris scans, which are part of the user's physical self, not an external device or application.

Concept tested: Multi-Factor Authentication (MFA) factors

Source: https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks

Topics

#authentication factors#MFA#something you have#TOTP

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice