Implementing Multifactor Authentication for VPN

Authentication and Access Control

A network manager wants to protect the company's VPN by implementing multifactor authentication that uses: Something you know - Something you have - Something you are - Which of the following would accomplish the manager's goal?

  1. Domain name, PKI, GeoIP lookup
  2. VPN IP address, company ID, facial structure
  3. Password, authentication token, thumbprint Source Reference Answer
  4. Company URL, TLS certificate, home address

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the ability to classify authentication factors; the trap lies in confusing network identifiers (like IP addresses or URLs) with actual user credentials.

This question tests the understanding of MFA factors by mapping specific credentials to 'something you know', 'have', and 'are'. Community consensus confirms that passwords, tokens, and biometrics are the standard examples for these respective categories.

Option B is a common distractor because it includes a biometric ('facial structure'), but 'VPN IP address' and 'company ID' do not represent valid 'know' or 'have' factors in the context of MFA implementation.

Community Discussion (4 comments)

Shaman73 👍 7
• C. Password, authentication token, thumbprint
deejay2 👍 1 Selected: C
I get the answer is C. However, why not B?
Rafili 👍 1 Selected: C
C, because: Something you know: In this case, it is the password that the user knows. Something you have: This refers to the authentication token that the user has, such as a hardware or software token. Something you are: This represents the thumbprint, which is a biometric method to verify the user's identity.
nesquick0 👍 4 Selected: C
C obviously

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option C correctly maps the three required MFA factors: a password represents 'something you know', an authentication token represents 'something you have', and a thumbprint represents 'something you are'. This combination provides robust security for a VPN connection by requiring distinct types of proof.

Why the Other Options Are Wrong

Options A, B, and D fail because they mix non-authentication attributes like GeoIP, TLS certificates, home addresses, and IP addresses. These are either environmental data, infrastructure configurations, or static identifiers, not dynamic user-held credentials required for MFA.

Community Comment Notes

Comment [3] provides the clearest breakdown, explicitly linking each item in Option C to its corresponding factor category. Comment [2] highlights a common confusion where users mistake any biometric option as correct without verifying the other two factors, emphasizing the need to check all components of the answer.

Exam Strategy

When answering MFA questions, always verify that the options cover different categories (knowledge, possession, inherence). Do not be distracted by technical terms like PKI or TLS unless they directly refer to the user's credential type.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide