220-1102 Security Practice Question
A company requires employees to present both a smart card and a PIN to log into their workstations. Which authentication principle is being implemented?
⚠ Common exam trap
The trap here is that candidates often mistake two separate items (smart card and PIN) for two factors, but the key is that they must come from different factor categories—possession and knowledge—to qualify as true two-factor authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Two-factor authentication
Two-factor authentication (2FA) requires two distinct categories of authentication factors. The smart card is a possession factor (something you have), and the PIN is a knowledge factor (something you know). Combining these two different factor types satisfies the definition of 2FA, whereas using two items from the same category would still be single-factor.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Single-factor authentication
Why it's wrong here
Single-factor authentication relies on exactly one category of credential, such as a password (knowledge) or an ID badge (possession). The scenario requires both a smart card and a PIN, which are two distinct categories—possession and knowledge—so it cannot be classified as single-factor. This choice fails because it ignores the second, independent factor being presented.
- ✓
Two-factor authentication
Why this is correct
Two-factor authentication (2FA) requires the user to present two different authentication factors from separate categories. Here, the smart card is a possession factor (something you have), and the PIN is a knowledge factor (something you know). Since both distinct factors are presented, this is the correct classification under the standard three-factor authentication framework.
- ✗
Biometric authentication
Why it's wrong here
Biometric authentication verifies identity using inherent physical or behavioral traits, such as fingerprints, iris patterns, or voiceprints, which fall under the 'something you are' factor. The described process uses a smart card and PIN, neither of which is a physical or behavioral characteristic. Thus, this option is incorrect because it describes a different authentication factor category entirely.
- ✗
Token-based authentication
Why it's wrong here
Token-based authentication commonly involves a hardware or software token (like a one-time-password generator) that acts as a possession factor—something you have. While a smart card is indeed a token, the additional PIN requirement makes this a multi-factor scenario, not a simple token-based single-factor process. Mislabeling it as token-based overlooks the complementary knowledge factor the PIN provides.
Go deeper
Related to this question
Learn chapter
Malware Types and Removal
Key term
One-time Password
A one-time password is a temporary, single-use code that authenticates a user for one login session or transaction.
Key term
Common Access Card
A Common Access Card (CAC) is a smart card issued by the U.S. Department of Defense that serves as a single identification, authentication, and access credential for military personnel and contractors.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.