A login can ask for two pieces of information and still rely on one factor category. For Security+ MFA questions, classify the evidence used to authenticate the person rather than counting the number of screens in the login flow.
Compare three original login examples
A system asks for a password and then a memorized PIN. Both are things the user knows. Two knowledge checks do not establish two different factor categories.
A second system asks for a password and a code from a separately possessed authenticator. This combines knowledge with possession in the simplified example.
A third system checks a biometric characteristic and requires possession of an enrolled security device. That can combine inherence with possession, depending on the system's actual design. You need the described verification process, not just the name of a gadget, to understand the factors.
Device unlock and remote authentication are different questions
A fingerprint may unlock a local device or authenticator. That does not necessarily mean the remote service receives the fingerprint. Real authentication systems can use local verification to authorize a cryptographic operation while keeping biometric data on the device.
In an exam scenario, do not invent an architecture the question has not described. The Security+ authentication practice questions are useful for checking whether you are classifying a memorized secret, possession of an authenticator, or a biometric characteristic.
MFA methods do not all resist the same attacks
An extra factor can improve protection, but some methods remain susceptible to phishing or approval manipulation. CISA's MFA guidance emphasizes the value of MFA and the move toward phishing-resistant methods.
This distinction matters when a question asks specifically for resistance to phishing. “Uses two steps” is not enough to prove that an option meets that stronger requirement. Also distinguish a request to identify factor categories from a request to choose the most appropriate authentication technology.
Review a wrong answer precisely
If you selected password plus PIN as two factors, correct the category error. If you correctly identified knowledge plus possession but missed the phishing-resistance requirement, your issue was a different one: you stopped before evaluating the requested protection.
Keep a short factor map beside the CompTIA Security+ identity study guide. Add one valid combination and one misleading combination, then explain each in plain language. For the next practice session, change the labels while preserving the factor categories. A “secret phrase” and a “security answer” are still both knowledge when both are memorized information, regardless of how different their names sound.