Courseiva
Security →easyMultiple Choice

220-1102 Security Practice Question

A company requires employees to present both a smart card and a PIN to log into their workstations. Which authentication principle is being implemented?

⚠ Common exam trap

The trap here is that candidates often mistake two separate items (smart card and PIN) for two factors, but the key is that they must come from different factor categories—possession and knowledge—to qualify as true two-factor authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Two-factor authentication

Two-factor authentication (2FA) requires two distinct categories of authentication factors. The smart card is a possession factor (something you have), and the PIN is a knowledge factor (something you know). Combining these two different factor types satisfies the definition of 2FA, whereas using two items from the same category would still be single-factor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Single-factor authentication

    Why it's wrong here

    Single-factor authentication relies on exactly one category of credential, such as a password (knowledge) or an ID badge (possession). The scenario requires both a smart card and a PIN, which are two distinct categories—possession and knowledge—so it cannot be classified as single-factor. This choice fails because it ignores the second, independent factor being presented.

  • ✓

    Two-factor authentication

    Why this is correct

    Two-factor authentication (2FA) requires the user to present two different authentication factors from separate categories. Here, the smart card is a possession factor (something you have), and the PIN is a knowledge factor (something you know). Since both distinct factors are presented, this is the correct classification under the standard three-factor authentication framework.

  • ✗

    Biometric authentication

    Why it's wrong here

    Biometric authentication verifies identity using inherent physical or behavioral traits, such as fingerprints, iris patterns, or voiceprints, which fall under the 'something you are' factor. The described process uses a smart card and PIN, neither of which is a physical or behavioral characteristic. Thus, this option is incorrect because it describes a different authentication factor category entirely.

  • ✗

    Token-based authentication

    Why it's wrong here

    Token-based authentication commonly involves a hardware or software token (like a one-time-password generator) that acts as a possession factor—something you have. While a smart card is indeed a token, the additional PIN requirement makes this a multi-factor scenario, not a simple token-based single-factor process. Mislabeling it as token-based overlooks the complementary knowledge factor the PIN provides.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.