Courseiva
Security Principles →mediumMultiple Select

ISC2 CC Security Principles Practice Question

A security administrator is reviewing the organization's authentication controls and wants to strengthen them by adding factors from different categories. Which TWO of the following represent distinct authentication factor categories that can be combined to achieve multi-factor authentication? (Choose two.)

⚠ Common exam trap

The trap here is treating any two credentials as multi-factor, when the factors must come from different categories such as knowledge and possession.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Something you possess, such as a smart card or hardware token

Multi-factor authentication requires two or more factors drawn from different categories: something you know, something you have, and something you are. A password or PIN represents knowledge, while a smart card or hardware token represents possession, so combining them satisfies the requirement. Usernames are identifiers rather than factors, two passwords remain knowledge-based, and a one-time passcode sent to the requesting device does not introduce a distinct factor category.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Two different passwords for the same account

    Why it's wrong here

    Requiring two passwords still relies entirely on knowledge factors, so it remains single-factor authentication. An attacker who compromises the user's knowledge, through phishing, keylogging, or credential stuffing, can defeat both passwords. Multi-factor authentication requires combining different factor categories, such as something you know with something you have or something you are. Using two passwords increases complexity but does not change the underlying factor type.

  • ✓

    Something you possess, such as a smart card or hardware token

    Why this is correct

    Possession factors are physical items the user has, including smart cards, hardware tokens, and registered mobile devices. Pairing a possession factor with a knowledge factor such as a PIN satisfies multi-factor authentication because the two factors come from different categories. Possession factors resist password guessing and replay because the attacker must also obtain the physical item. This is a standard factor category in authentication frameworks.

  • ✓

    Something you know, such as a password or PIN

    Why this is correct

    Knowledge factors are information the user memorizes or knows, like a password, passphrase, or PIN. Combining a knowledge factor with a factor from another category, such as a hardware token the user possesses, creates true multi-factor authentication. On its own a password is single-factor, which is why it is frequently paired with possession or inherence factors. This category is one of the standard factor types used in authentication design.

  • ✗

    A one-time passcode sent to the same device that is requesting access

    Why it's wrong here

    Delivering a one-time passcode to the same device that is requesting access does not add a separate factor category. If the device is already compromised or in the attacker's control, the attacker can read the code and complete authentication. For stronger assurance, the second factor should come from a different category and ideally a separate channel or device, such as a hardware token or authenticator app on a distinct device.

  • ✗

    A username and a password entered together

    Why it's wrong here

    A username is an identifier, not an authentication factor, and the password is a single knowledge factor. Entering both does not create multi-factor authentication because both elements belong to the same category of something you know. True multi-factor authentication requires factors from different categories, such as knowledge plus possession or inherence. This combination therefore does not strengthen authentication beyond single-factor password authentication.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.