Which additional physical control enforces MFA with existing badges?
In order to improve the security of a company, an information security officer decided to implement multifactor authentication (MFA) technology. The company currently requires badges to access its facilities. Which of the following additional types of physical controls should the security officer recommend to enforce MFA?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests your understanding of MFA factor categories and specifically asks for a physical control, which eliminates knowledge-based factors like passwords or PINs and also rules out location-based context.
In CompTIA PT0-002, MFA requires combining two or more authentication factors. When badges (something you have) are already used, the recommended additional physical control is a biometric factor such as a fingerprint, making 'Who you are' the correct answer.
A common mistake is choosing 'What you know' because it is a standard MFA factor, but it is not a physical control; it is a knowledge-based factor and would be implemented as a technical control (e.g., password or PIN), not a physical one.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
MFA requires two or more independent authentication factors. The company already has badges, which represent the 'what you have' factor. To enforce MFA with a physical control, the next factor should be biometric—something inherent to the person's physical characteristics, such as a fingerprint, retinal scan, or facial recognition. This is exactly the 'who you are' factor and is a physical control. Community comment [1] confirms that real data centers use badge + fingerprint, and comment [2] explains that 'Who you are' encompasses physical biometric controls.
Why the Other Options Are Wrong
'What you have' is the badge already in use, so it cannot be the additional factor. 'Where you are' is a location-based context factor, not a universally recognized physical control and not suitable as a second authentication factor in this scenario. 'What you know' refers to passwords, PINs, or passphrases; these are knowledge-based and are technical controls, not physical. Comment [2] directly states that knowledge is not a physical control and that location is not a physical control either.
Community Comment Notes
Community members overwhelmingly selected D with 100% of votes. Comment [2] provides the clearest rationale: it eliminates each wrong option and highlights that 'Who you are' includes biometric factors. Comment [1] adds real-world context, noting that data centers almost always combine badges with fingerprints rather than passcodes. Comment [3] reinforces the distinction that 'What you know' would be a technical control, while a fingerprint is a physical control.
Official Reference
Exam Strategy
When a question asks for a 'physical control' in MFA, immediately focus on factors that are tangible or inherent to a person, such as biometrics ('who you are'). Eliminate knowledge factors like passwords and PINs, and do not confuse location context with a traditional MFA factor.