Courseiva
Security Principles →mediumMultiple Choice

ISC2 CC Security Principles Practice Question

A retail company wants to reduce the risk of fraudulent online purchases. The security manager proposes requiring customers to enter a password plus a code sent to their registered mobile phone. Which security concept does this proposal best illustrate?

⚠ Common exam trap

The trap here is assuming any two-step login is multi-factor, but two passwords or two codes from the same factor category would still be single-factor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multi-factor authentication

Multi-factor authentication combines factors from different categories, such as something you know and something you have. The password represents knowledge, while the code sent to a registered mobile phone represents possession of that device. This pairing raises the difficulty for an attacker who steals only the password, so the proposal is best described as multi-factor authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Federated identity

    Why it's wrong here

    Federated identity allows a user to authenticate across multiple systems using a trusted identity provider, often with standards like SAML or OpenID Connect. The scenario describes a direct login with password and phone code, not trust between organizations or domains. Thus federated identity is not the concept being applied.

  • ✗

    Single sign-on

    Why it's wrong here

    Single sign-on lets a user authenticate once and access multiple applications without re-entering credentials. The scenario does not mention accessing multiple systems after one login; it focuses on strengthening a single authentication event. Therefore, single sign-on is not the correct description of this proposal.

  • ✗

    Single-factor authentication

    Why it's wrong here

    Single-factor authentication uses only one category of evidence, such as a password. Here, the customer must also provide a code sent to a registered phone, which is a separate factor. Therefore, this proposal goes beyond single-factor authentication and is not the best description of the scenario.

  • ✓

    Multi-factor authentication

    Why this is correct

    Multi-factor authentication requires two or more different factor types, such as something you know and something you have. A password is knowledge, and a code sent to a registered phone is possession of that device. Combining them satisfies the definition, so this proposal correctly illustrates multi-factor authentication.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.