nerdexam
CompTIA

SY0-501 · Question #362

Users in a corporation currently authenticate with a username and password. A security administrator wishes to implement two-factor authentication to improve security. Which of the following…

The correct answer is C. Smart card. To implement two-factor authentication, a second, distinct authentication factor must be added to the existing username and password. A smart card provides the 'something you have' factor necessary to achieve this goal.

Submitted by valeria.br· Mar 4, 2026General security concepts

Question

Users in a corporation currently authenticate with a username and password. A security administrator wishes to implement two-factor authentication to improve security. Which of the following authentication methods should be deployed to achieve this goal?

Options

  • APIN
  • BSecurity question
  • CSmart card
  • DPassphrase
  • ECAPTCHA

How the community answered

(34 responses)
  • A
    9% (3)
  • B
    6% (2)
  • C
    82% (28)
  • E
    3% (1)

Why each option

To implement two-factor authentication, a second, distinct authentication factor must be added to the existing username and password. A smart card provides the 'something you have' factor necessary to achieve this goal.

APIN

A PIN is a 'something you know' factor, which, when combined with a password, still only constitutes a single authentication factor type.

BSecurity question

A security question is also a 'something you know' factor, and does not introduce a second, distinct type of authentication factor.

CSmart cardCorrect

A smart card represents the 'something you have' authentication factor. When combined with a PIN or password (the 'something you know' factor) to unlock its credentials, it provides two distinct factors. This combination achieves two-factor authentication by requiring two different categories of proof of identity.

DPassphrase

A passphrase is an extended form of a password and falls under the 'something you know' category, thus not providing a second authentication factor type.

ECAPTCHA

A CAPTCHA is a mechanism to verify that a user is human and is not considered an authentication factor for identity verification.

Concept tested: Multifactor authentication (MFA) factors

Source: https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks

Topics

#multi-factor authentication#smart card#authentication factors#2FA

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice