Which MFA Solution Meets Know/Are/Have Without Extra Costs?
A company wants to add an MFA solution for all employees who access the corporate network remotely. Log-in requirements include something you know, are, and have. The company wants a solution that does not require purchasing third-party applications or specialized hardware. Which of the following MFA solutions would best meet the company's requirements?
Community Votes
61% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests whether you recognize that modern smartphones already include native biometric scanners and free enterprise authenticator apps, satisfying the 'no purchased third-party applications' constraint while delivering stronger security than SMS-based alternatives.
This question evaluates your ability to map multi-factor authentication categories to practical, cost-effective deployments. The community consensus strongly favors mobile app-generated OTPs combined with biometrics, as they fulfill all three authentication factors using native smartphone features without requiring additional purchases.
Candidates frequently select SMS-based options because they misinterpret 'third-party applications' as requiring a purchase, overlooking that SMS is heavily discouraged by CompTIA due to SIM-swapping vulnerabilities and that native OS biometrics eliminate the need for extra hardware.
Community Discussion (12 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Authentication Factor Mapping
Multi-factor authentication (MFA) requires combining distinct credential categories: something you know (passwords/PINs), something you have (physical devices/tokens), and something you are (biometrics). The scenario mandates all three while explicitly prohibiting additional hardware costs or paid software licenses.Why Option D is Correct
Option D pairs a mobile application-generated one-time passcode (OTP) with facial recognition. Modern smartphones ship with operating-system-level biometric scanners (e.g., FaceID, Windows Hello) that serve as native 'something you are' factors at no extra cost. Additionally, corporate authenticator apps are typically distributed free through enterprise portals or pre-installed, meaning they do not violate the 'no purchased third-party applications' rule. This configuration securely fulfills all three factors while aligning with CompTIA’s emphasis on scalable, budget-conscious IAM strategies.Why Other Options Fall Short
- Option A specifies a smart card, which directly contradicts the prohibition on specialized hardware.
- Option B relies on security questions, which are inherently weak, easily researched, and lack a true 'something you are' component.
- Option C is the primary distractor. While SMS technically requires no new app, CompTIA consistently warns against SMS-based MFA due to SIM-swapping and interception risks. The community vote distribution (59% D vs 37% C) highlights a common trap regarding 'third-party applications,' but as noted by top-voted candidates, native smartphone features and free enterprise authenticators bypass this constraint entirely while providing significantly better security posture.
Official Reference
Exam Strategy
When analyzing MFA scenarios, immediately map each option to the three authentication factors before evaluating cost constraints. Remember that operating-system-native biometrics and vendor-provided free authenticator apps are treated as zero-cost deployments in CompTIA’s framework, making them strictly superior to legacy methods like SMS or security questions.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →