Courseiva
Access Controls Concepts →mediumMultiple Choice

ISC2 CC Access Controls Concepts Practice Question

A financial services company issues every employee a smart card that must be inserted into a reader before the employee can log in to a workstation. The card stores a private key that never leaves the card. Which authentication factor category does the smart card represent in this scenario?

⚠ Common exam trap

The trap here is treating the smart card as a knowledge factor simply because it may be unlocked with a PIN, when the device itself demonstrates possession rather than memorized knowledge.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Something you have

A smart card is a possession factor because the employee must physically hold and present the token, and the embedded private key enables cryptographic proof that the token is present. It is commonly combined with a PIN or password to achieve multifactor authentication, pairing what the user has with what the user knows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Something you know

    Why it's wrong here

    Something you know refers to memorized secrets such as passwords or PINs. The smart card is a physical object the employee possesses, and its private key is not something the user recites or remembers. Although the card may be protected by a PIN, the card itself is not a knowledge factor, so this category does not describe the device.

  • ✗

    Something you are

    Why it's wrong here

    Something you are refers to biometric characteristics such as fingerprints, iris patterns, or voice. The smart card is a manufactured device carried by the employee, not a physical trait of the person. While biometrics can be stored on a smart card for convenience, the card's role here is possession-based authentication of a token, not measurement of a biological feature.

  • ✓

    Something you have

    Why this is correct

    Something you have is a possession factor, and the smart card is a physical token the employee holds and inserts into a reader. The card performs cryptographic operations with a private key that never leaves it, proving possession. This is the classic example of a possession factor used in multifactor authentication, distinct from memorized secrets or biometric traits.

  • ✗

    Somewhere you are

    Why it's wrong here

    Somewhere you are is a location-based factor, often derived from network address, GPS, or physical presence at a specific facility. The scenario does not restrict login by location; it requires insertion of a physical card. Location may be used as a supplementary condition, but the smart card itself authenticates possession of a credential, not the user's whereabouts.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.