CompTIA SecurityX CAS-005 (V5) Practice Question

A security architect is designing an MFA policy for a critical system. The proposed authentication process requires users to enter their password, followed by a time-based one-time password (TOTP) from an authenticator app on their smartphone, and then a final code sent via SMS to the same smartphone. Which of the following statements BEST explains the security flaw in this proposed process?

  • SMS-based authentication is vulnerable to SIM-swapping attacks and is no longer considered a secure practice.

  • Requiring three authentication steps creates excessive user friction and negatively impacts productivity.

  • Time-based one-time passwords (TOTP) are a knowledge factor, not a possession factor.

  • The authenticator app and the SMS code both represent the same possession factor because they are tied to a single device.

CompTIA SecurityX CAS-005 (V5)
Security Engineering
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $64
$529.00 $465.00
SAVE $70
CompTIA SecurityX Voucher with Retake
v5 / CAS-005
Includes Retake
$578.00 $508.00
Bash, the Crucial Exams Chat Bot
AI Bot