ISC2 CC Access Controls Concepts Practice Question
A financial services company issues every employee a smart card that must be inserted into a reader before the employee can log in to a workstation. The card stores a private key that never leaves the card. Which authentication factor category does the smart card represent in this scenario?
⚠ Common exam trap
The trap here is treating the smart card as a knowledge factor simply because it may be unlocked with a PIN, when the device itself demonstrates possession rather than memorized knowledge.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Something you have
A smart card is a possession factor because the employee must physically hold and present the token, and the embedded private key enables cryptographic proof that the token is present. It is commonly combined with a PIN or password to achieve multifactor authentication, pairing what the user has with what the user knows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Something you know
Why it's wrong here
Something you know refers to memorized secrets such as passwords or PINs. The smart card is a physical object the employee possesses, and its private key is not something the user recites or remembers. Although the card may be protected by a PIN, the card itself is not a knowledge factor, so this category does not describe the device.
- ✗
Something you are
Why it's wrong here
Something you are refers to biometric characteristics such as fingerprints, iris patterns, or voice. The smart card is a manufactured device carried by the employee, not a physical trait of the person. While biometrics can be stored on a smart card for convenience, the card's role here is possession-based authentication of a token, not measurement of a biological feature.
- ✓
Something you have
Why this is correct
Something you have is a possession factor, and the smart card is a physical token the employee holds and inserts into a reader. The card performs cryptographic operations with a private key that never leaves it, proving possession. This is the classic example of a possession factor used in multifactor authentication, distinct from memorized secrets or biometric traits.
- ✗
Somewhere you are
Why it's wrong here
Somewhere you are is a location-based factor, often derived from network address, GPS, or physical presence at a specific facility. The scenario does not restrict login by location; it requires insertion of a physical card. Location may be used as a supplementary condition, but the smart card itself authenticates possession of a credential, not the user's whereabouts.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
Common Access Card
A Common Access Card (CAC) is a smart card issued by the U.S. Department of Defense that serves as a single identification, authentication, and access credential for military personnel and contractors.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.