A+ Lesson

MFA Methods and Authentication Factors for A+

Last updated: 6/10/2026

Short answer

MFA strengthens sign-in by combining different factor categories so that compromising a password alone is insufficient. Common delivery and proof methods include authenticator applications (TOTP), hardware tokens, SMS or voice-delivered codes, and emailed codes or links. At technician level, the key skills are recognizing the method when troubleshooting (e.g., user not receiving SMS vs. app-generated code) and understanding that two passwords do not equal MFA.

Why it appears on the exam

- Identify whether a described code is TOTP (time-based) or a delivered OTP via SMS/email. - Choose likely root causes in support scenarios: wrong phone number for SMS, time drift for an authenticator app, lost hardware token.

Key concepts

Concept 1

Required terms

multifactor authentication (MFA): Authentication requiring two or more different categories of proof (something you know, something you have, something you are). authentication factor: A category of proof used for authentication: knowledge, possession, or inherence (biometric). email: A delivery method that sends a one-time code or approval link to a user's email address as part of verification. hardware token: A physical device that generates or displays a one-time code or performs cryptographic approval for sign-in.

Example

A user is prevented from signing in because their phone for SMS codes changed -> support should verify/update the registered delivery method.

Concept 2

How MFA Methods and Authentication Factors works

MFA strengthens sign-in by combining different factor categories so that compromising a password alone is insufficient. Common delivery and proof methods include authenticator applications (TOTP), hardware tokens, SMS or voice-delivered codes, and emailed codes or links. At technician level, the key skills are recognizing the method when troubleshooting (e.g., user not receiving SMS vs. app-generated code) and understanding that two passwords do not equal MFA.

Example

A technician helps a user enroll an authenticator app when their hardware token is lost -> solution is to re-enroll or provide alternate MFA recovery per policy.

Concept 3

Common confusion

A common issue is treating two knowledge-based factors (two passwords) as MFA; they are not. Also, SMS-based MFA is often treated as equivalent security to hardware tokens or app TOTP, though SMS has practical attack risks.

Example

A user is prevented from signing in because their phone for SMS codes changed -> support should verify/update the registered delivery method.

Concept 4

Core 2 (220-1202) question cues

Identify whether a described code is TOTP (time-based) or a delivered OTP via SMS/email; Choose likely root causes in support scenarios: wrong phone number for SMS, time drift for an authenticator app, lost hardware token.

Example

A technician helps a user enroll an authenticator app when their hardware token is lost -> solution is to re-enroll or provide alternate MFA recovery per policy.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.A technician is troubleshooting this situation: A user is prevented from signing in because their phone for SMS codes changed -> support should verify/update the registered delivery method. What should they identify?

Q2.A support ticket includes this clue: A technician helps a user enroll an authenticator app when their hardware token is lost -> solution is to re-enroll or provide alternate MFA recovery per policy. Which concept is being tested?

Q3.An A+ support scenario describes this situation: A delivery method that sends a one-time code or approval link to a user's email address as part of verification. Which answer fits best?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8