FC0-U71 Security Practice Question
An organization implements a security control that requires users to swipe a smart card and then enter a PIN to access a secure facility. Which combination of authentication factors does this represent?
⚠ Common exam trap
The trap is that candidates must correctly categorize each credential into the right factor class — many mistakenly classify a PIN as 'something you are' or a smart card as 'something you know,' or fail to recognize that two different categories are required for MFA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Something you have and something you know
A smart card is a physical token the user possesses, satisfying 'something you have,' while a PIN is a memorized secret, satisfying 'something you know.' Combining these two different factor categories constitutes multi-factor authentication (MFA), which is stronger than single-factor or same-category authentication. This is a classic two-factor physical access control scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Something you are and something you have
Why it's wrong here
A smart card is something you have, but a PIN is something you know, not something you are; biometrics such as fingerprints or iris scans constitute inherence. It is tempting because both factors are possessed by the user, but the PIN is memorised knowledge, making the pairing possession plus knowledge.
- ✗
Something you know and something you do
Why it's wrong here
A smart card is something you have, not something you do; the PIN is something you know, so the pairing is possession plus knowledge. The 'something you do' factor covers behavioural biometrics such as typing rhythm or signature dynamics, which this scenario never measures.
- ✓
Something you have and something you know
Why this is correct
A smart card is a physical token, satisfying something you have, while the PIN is memorised knowledge, satisfying something you know. Combining these two distinct factor categories constitutes multi-factor authentication, exactly as the stem's swipe-then-PIN control requires.
- ✗
Something you know and something you are
Why it's wrong here
The smart card supplies something you have, not something you are; the PIN supplies knowledge. 'Something you are' means an inherent physical or physiological trait, such as a fingerprint or iris pattern, captured by a biometric reader, which no step here performs.
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.