A company wants to add an MFA solution for all employees who access the corporate network remotely. Log-in requirements include something you know, are, and have. The company wants a solution that does not require purchasing third-party applications or specialized hardware. Which of the following MFA solutions would best meet the company's requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Mobile application-generated, one-time passcode with facial recognition.
Why this is the answer
The correct answer is Mobile application-generated, one-time passcode with facial recognition. This option satisfies all three MFA factors: "something you know" (the mobile app PIN or device unlock), "something you are" (facial recognition), and "something you have" (the mobile device generating the OTP). It also avoids purchasing specialized hardware or third-party applications, as most modern smartphones support these capabilities natively. Smart card with PIN and password is incorrect because a smart card is specialized hardware. Security questions and a one-time passcode sent via email is incorrect because security questions are a weak form of "something you know" and email can be compromised, making it less secure, and it lacks a "something you are" factor. Voice and fingerprint verification with an SMS one-time passcode is incorrect because voice verification can be spoofed and SMS OTPs are vulnerable to SIM-swapping attacks, and it also doesn't explicitly include a "something you have" factor beyond the phone itself for SMS.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed