Courseiva
Security Principles →mediumMultiple Choice

ISC2 CC Security Principles Practice Question

A financial institution wants to implement a control that verifies the identity of a user by requiring something the user knows and something the user has. Which of the following authentication mechanisms best meets this requirement?

⚠ Common exam trap

The trap here is assuming that any two authentication methods constitute multi-factor authentication, when they must be of different factor types.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Smart card and PIN

Multi-factor authentication requires combining two or more different types of factors: something you know, something you have, something you are, somewhere you are, or something you do. The scenario explicitly requires something the user knows and something the user has. A smart card (possession) and a PIN (knowledge) meet this requirement, while the other options use factors of the same type or do not include a possession factor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Fingerprint and retina scan

    Why it's wrong here

    A fingerprint and a retina scan are both inherence factors (something the user is). Using two biometric factors does not meet the requirement of combining something the user knows with something the user has. While biometrics can be strong, they are both of the same factor type, so this is not true multi-factor authentication as specified.

  • ✓

    Smart card and PIN

    Why this is correct

    A smart card is a possession factor (something the user has), and a PIN is a knowledge factor (something the user knows). Combining these two satisfies the requirement of using something the user knows and something the user has. This is a classic example of multi-factor authentication that strengthens identity verification by requiring two different types of credentials.

  • ✗

    Username and password

    Why it's wrong here

    A username and password are both knowledge-based factors. The username is an identifier, and the password is a knowledge factor. This does not include a possession factor, so it fails to meet the requirement of something the user knows and something the user has. This is single-factor authentication, which is more susceptible to compromise.

  • ✗

    Password and security question

    Why it's wrong here

    A password and a security question are both knowledge-based factors (something the user knows). This does not satisfy the requirement of combining something the user knows with something the user has. Using two knowledge factors is weaker than true multi-factor authentication because both can be compromised through similar means, such as phishing or social engineering.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.