Which MFA Solution Meets Know/Are/Have Without Extra Costs?

A company wants to add an MFA solution for all employees who access the corporate network remotely. Log-in requirements include something you know, are, and have. The company wants a solution that does not require purchasing third-party applications or specialized hardware. Which of the following MFA solutions would best meet the company's requirements?

  1. Smart card with PIN and password
  2. Security questions and a one-time passcode sent via email
  3. Voice and fingerprint verification with an SMS one-time passcode
  4. Mobile application-generated, one-time passcode with facial recognition Source Reference Answer

Community Votes

D
61%
C
39%

61% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests whether you recognize that modern smartphones already include native biometric scanners and free enterprise authenticator apps, satisfying the 'no purchased third-party applications' constraint while delivering stronger security than SMS-based alternatives.

This question evaluates your ability to map multi-factor authentication categories to practical, cost-effective deployments. The community consensus strongly favors mobile app-generated OTPs combined with biometrics, as they fulfill all three authentication factors using native smartphone features without requiring additional purchases.

Candidates frequently select SMS-based options because they misinterpret 'third-party applications' as requiring a purchase, overlooking that SMS is heavily discouraged by CompTIA due to SIM-swapping vulnerabilities and that native OS biometrics eliminate the need for extra hardware.

Community Discussion (12 comments)

Anyio 👍 6 Selected: D
D. Mobile application-generated, one-time passcode with facial recognition Explanation: To meet the requirements of "something you know, are, and have" while avoiding additional costs for third-party apps or hardware: Something you know: Password or PIN. Something you have: A mobile device generating a one-time passcode. Something you are: Facial recognition (biometric verification). Option D leverages mobile devices employees already own, removing the need for specialized hardware or third-party applications while meeting the MFA criteria. Why not the other options? A: Smart cards require specialized hardware. B: Security questions are weak (easily guessed) and do not qualify as “something you are.” C: Voice verification systems often require additional infrastructure and are less practical compared to mobile solutions.
prabh1251 👍 1 Selected: C
D is incorrect - mobile application-generated passcode, which typically requires a third-party app like Google Authenticator or Microsoft Authenticator.. C is correct - No third-party app ✔️ ✅ No extra hardware ✔️ ✅ Covers "something you know, are, and have"
Nahidwin 👍 1 Selected: C
The question is written very poorly , i think its C because it says without the need for purchasing a third party application , SMS don't require an application , anyway GREAT QUSTION COMPTIA !
DaBulls 👍 4 Selected: D
D. Mobile application-generated, one-time passcode with facial recognition Why? Something you know → The password Something you have → The mobile device with the authentication app generating a one-time passcode (OTP) Something you are → Facial recognition NOT: C. Voice verification is unreliable, and SMS OTPs are vulnerable to SIM-swapping attacks.
Bunaventi 👍 1 Selected: D
GPT: Both CompTIA and Cisco would recommend D. Mobile application-generated, one-time passcode with facial recognition as the best MFA solution. It meets the “know, are, and have” requirements while avoiding additional hardware or third-party application costs, making it secure, practical, and cost-effective.
Aces155 👍 1 Selected: C
I think the answer is C. In both C and D, the something you have would have to be considered the phone you’re receiving the code on. I think D is incorrect because the question specifically says “does not require purchasing third party applications or specialized hardware.” While I use rsa and Microsoft Authenticator at work, both of which are free, i think specifically within the context of this question, D would be incorrect because it indicates the use of a third party application.
pierregates5 👍 2 Selected: C
the question states "without purchasing a third party application" so D is out of the question
Danny_Note 👍 1 Selected: B
B. The question specifies that the methods should include something you know and something you have. That means it can't be C or D which rely on something you are. Further, they don't want to buy extra hardware. That means option A is out because of smart cards. only B fits the description.
Fhaddad81 👍 3 Selected: D
Mobile application-generated, one-time passcode with facial recognition
ProudFather 👍 3 Selected: C
This option best meets the company's requirements for an MFA solution that does not require third-party applications or specialized hardware: Something you know: Password Something you are: Voice and fingerprint verification Something you have: SMS one-time passcode
HQvRuss 👍 2 Selected: D
D. Mobile application-generated, one-time passcode with facial recognition Explanation: The company's MFA requirements include something you know, something you have, and something you are
csamuels71 👍 2 Selected: C
This is wrong nothing states something you!!!

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Authentication Factor Mapping

Multi-factor authentication (MFA) requires combining distinct credential categories: something you know (passwords/PINs), something you have (physical devices/tokens), and something you are (biometrics). The scenario mandates all three while explicitly prohibiting additional hardware costs or paid software licenses.

Why Option D is Correct

Option D pairs a mobile application-generated one-time passcode (OTP) with facial recognition. Modern smartphones ship with operating-system-level biometric scanners (e.g., FaceID, Windows Hello) that serve as native 'something you are' factors at no extra cost. Additionally, corporate authenticator apps are typically distributed free through enterprise portals or pre-installed, meaning they do not violate the 'no purchased third-party applications' rule. This configuration securely fulfills all three factors while aligning with CompTIA’s emphasis on scalable, budget-conscious IAM strategies.

Why Other Options Fall Short

  • Option A specifies a smart card, which directly contradicts the prohibition on specialized hardware.
  • Option B relies on security questions, which are inherently weak, easily researched, and lack a true 'something you are' component.
  • Option C is the primary distractor. While SMS technically requires no new app, CompTIA consistently warns against SMS-based MFA due to SIM-swapping and interception risks. The community vote distribution (59% D vs 37% C) highlights a common trap regarding 'third-party applications,' but as noted by top-voted candidates, native smartphone features and free enterprise authenticators bypass this constraint entirely while providing significantly better security posture.

Official Reference

Exam Strategy

When analyzing MFA scenarios, immediately map each option to the three authentication factors before evaluating cost constraints. Remember that operating-system-native biometrics and vendor-provided free authenticator apps are treated as zero-cost deployments in CompTIA’s framework, making them strictly superior to legacy methods like SMS or security questions.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide