exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 624 discussion

Actual exam question from CompTIA's SY0-501
Question #: 624
Topic #: 1
[All SY0-501 Questions]

An organization hosts a public-facing website that contains a login page for users who are registered and authorized to access a secure, non-public section of the site. That non-public site hosts information that requires multifactor authentication for access. Which of the following access management approaches would be the BEST practice for the organization?

  • A. Username/password with TOTP
  • B. Username/password with pattern matching
  • C. Username/password with a PIN
  • D. Username/password with a CAPTCHA
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Faiz
Highly Voted 5 years, 6 months ago
TOTP - Something you have User name and password - Something you know
upvoted 17 times
[Removed]
5 years, 2 months ago
TOTP isn't something you have. Something you have is more like a fob or government cac card or PIV. Something physical.
upvoted 3 times
Meredith
5 years, 2 months ago
TOTP is definitely something you have per Darrel Gibson's book.
upvoted 28 times
Lucky_Alex
5 years, 1 month ago
TOTP is time-based one-time password, that is not related to this case CAPTCHA is used to identify whether the one logging in is a human or not. In a Captcha Verification, the user is presented with a picture (or “challenge”) of words or characters, and the user must correctly type out those characters in order to proceed. So the provided answer is correct. It's D.
upvoted 9 times
MagicianRecon
5 years, 1 month ago
TOTP is not related ? Lol ... CAPTCHA does not seem to be related. How is that an authentication? It is used to differentiate b/w a human from a bot and protect agains spam bots
upvoted 13 times
...
...
...
MagicianRecon
5 years, 1 month ago
TOTP can be disputed to be honest but literature says that is is indeed "something you have" and most orgs like google, fb, twitter when using multi factor auth do use a TOTP. Same thing that banking apps use
upvoted 4 times
...
...
...
success101
Highly Voted 5 years, 6 months ago
Its A.
upvoted 14 times
...
Eluis007
Most Recent 3 years, 8 months ago
Discuss more, we need more comments about this simple question
upvoted 1 times
...
mxh778872
3 years, 10 months ago
CAPTCHA is something you do.
upvoted 1 times
...
fonka
4 years, 1 month ago
Correction. Answer is A
upvoted 1 times
...
fonka
4 years, 1 month ago
A and c
upvoted 1 times
...
hakanb
4 years, 1 month ago
`A Time-based One-Time Password (TOTP) is similar to HOTP, but it uses a timestamp instead of a counter. One-time passwords created with TOTP typically expire after 30 seconds.` so isnt it clear that the answer is A ? The best and practical way to authenticate so many people by eliminating most of the security issues
upvoted 1 times
...
StickyMac
4 years, 2 months ago
multifactor authentication for access, means have two authentication validations for accessing site. When you entering username/password that is one part of authentication. when you matching blocks of pictures or writing words that makes a seconds part of you being authenticated. CAPCHA does test you make sure you are not a Bot and NOT trying to brake in to a authenticated site. I hope it make sense folks. Still learning Security and trying to find best explanations.
upvoted 1 times
...
KRone
4 years, 3 months ago
Both HMAC-Based One-time Password Algorithms (HOTP) and Time-Based One-time Password Algorithms (TOTP) generate these tokens.
upvoted 1 times
...
loophole
4 years, 4 months ago
Keywords is "Multifactor Authentication" - TOTP is something you have. CAPTCHA is a verification method and not an authentication method. Answer is A
upvoted 1 times
...
Matrix141
4 years, 5 months ago
CompTIA Security+ Study Guide: Exam SY0-501: Something you know, such as a password or PIN. This is often referred to as Type I. Something you have, such as a smartcard, token, or identification device. This is often referred to as Type II. Something you are, such as your fingerprints or retinal pattern (often called biometrics). This is often referred to as Type III. Something you do, such as an action you must take to complete authentication. This does not have a type (I, II, III). Somewhere you are (this is based on geolocation). This does not have a type (I, II, III). https://en.wikipedia.org/wiki/Multi-factor_authentication A good example of two-factor authentication is the withdrawing of money from an ATM; only the correct combination of a bank card (something the user possesses) and a PIN (something the user knows) allows the transaction to be carried out. Two other examples are to supplement a user-controlled password with a one-time password (OTP) or code generated or received by an authenticator (e.g. a security token or smartphone) that only the user possesses If it was the pattern of the iris or something like that, there is no doubt that B. But in this case, I would answer A.
upvoted 2 times
...
mdsabbir
4 years, 5 months ago
Its TOTP as TOTP is soft token. Its used for two factor authentication.
upvoted 2 times
...
Orkhann
4 years, 6 months ago
Answer is B. OTP is not something you have according to Comptia official study guide. They say it is something you know.
upvoted 1 times
wraith13
4 years, 6 months ago
A.Y.E 🤘🏻
upvoted 1 times
haskins5763
4 years, 1 month ago
In every CompTIA Security + study guide/exam prep I’ve read a OTP/TOTP is generated by a physical token, and is absolutely SOMETHING YOU HAVE 🤦‍♂️
upvoted 1 times
...
...
...
vi2
4 years, 6 months ago
Answer is A. Not sure why people are trying to convince themselves that it's D.
upvoted 1 times
...
certpro
4 years, 7 months ago
keywords are "hosts information" and "Best Practice for organization" gives D
upvoted 1 times
...
WFT_2020
4 years, 8 months ago
Registered users enter username/password + CAPTCHA just to gain access to the logon page for the non-public site. ThEN multifactored authentication is used. Right? So answer D may make sense in that context. Unless I'm dumb, high or both.
upvoted 2 times
Heymannicerouter
4 years, 3 months ago
CAPTCHA isn't an authentication method.
upvoted 2 times
...
...
addyp1999
4 years, 8 months ago
Wouldn't CAPTCHA be something you DO because you have to do it correctly? like type the captcha or identify fire hydrants or spin the tiger statue till it's upright? I also agree that TOTP would be something you have that is valid for a moment but on the contrary, once you get the TOTP "YOU KNOW THE 6 digit CODE or whatever" right? My exams in 2 days I could go with either.
upvoted 1 times
addyp1999
4 years, 8 months ago
I know CAPTCHA would only authenticate you as "HUMAN" it can't relate you with a user account owner's identity. IDK man good luck
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...