ISC2 CC Access Controls Concepts Practice Question
A hospital's radiology department issues each technologist a smart card that must be inserted into a workstation reader before the technologist types a username and password. The smart card stores a digital certificate that the workstation validates. Which statement best describes how this arrangement maps to the identity and access control concepts?
⚠ Common exam trap
The trap here is assuming that any second credential automatically becomes the identification step rather than remaining part of authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The username provides identification, while the smart card and password together provide authentication.
Identification is the act of claiming an identity, and authentication is the act of proving that claim. Typing a username claims an identity, while the smart card and password independently verify it using possession and knowledge factors. Because two distinct factor types are required, the workflow is multi-factor authentication, and authorization would only follow once verification succeeds.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The entire sequence is authorization, because the workstation validates a digital certificate.
Why it's wrong here
Authorization is the process of determining what an authenticated subject is permitted to do, such as which patient records can be opened. Certificate validation occurs during authentication to confirm the credential is trustworthy. No permission decision is described in the scenario, so labeling the sequence authorization misstates the purpose of the certificate check.
- ✓
The username provides identification, while the smart card and password together provide authentication.
Why this is correct
The user states who they claim to be by entering a username, which is identification. The system then verifies that claim through the smart card (something you have) and the password (something you know), which constitute authentication. This two-factor validation matches the classic definition of authentication as proving a claimed identity before authorization is evaluated.
- ✗
The smart card performs identification, while the username and password perform authentication.
Why it's wrong here
A smart card plus a typed credential is a multi-factor arrangement, but the card itself does not serve as the claim of identity. Identification is the act of presenting a claimed identity to the system, which in this workflow is still the username. The card contributes an authentication factor, not the identity claim, so this description misplaces the roles.
- ✗
The smart card and password together perform identification, while the username performs authentication.
Why it's wrong here
This reverses the two concepts. Identification is always the presentation of a claimed identity, typically a username, account number, or similar identifier. Authentication is the verification of that claim using one or more factors. The smart card and password verify the identity claim, they do not establish which identity is being claimed.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.