Courseiva
Security Principles →mediumMultiple Select

ISC2 CC Security Principles Practice Question

A security analyst is designing a multi-factor authentication system for remote access. Which TWO of the following combinations represent true multi-factor authentication? (Select TWO)

⚠ Common exam trap

The trap is that candidates see two different-looking authentication methods and assume MFA, without checking whether both factors belong to the same category (e.g., two biometrics or two knowledge factors).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Fingerprint and password

Option B (fingerprint and password) is correct because it combines a biometric inherence factor (the fingerprint) with a knowledge factor (the password), satisfying true MFA by mixing two different factor categories. Option C (password and smart card) is correct because it pairs a knowledge factor (the password) with a possession factor (the smart card, something you have), which are distinct factor types. Option A (smart card and OTP token) is not true MFA because both are possession factors (something you have), even though they are different technologies. Option D (fingerprint and retina scan) is not true MFA because both are biometric inherence factors (something you are). Option E (password and PIN) is not true MFA because both are knowledge factors (something you know).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Smart card and OTP token

    Why it's wrong here

    A smart card and an OTP token both satisfy the possession factor, so combining them yields single-factor authentication, not true MFA. It tempts because two separate physical devices appear to strengthen access; a smart card would be correct when paired with a PIN or biometric from a different factor.

  • ✓

    Fingerprint and password

    Why this is correct

    A fingerprint is something you are (inherence), while a password is something you know (knowledge). Pairing them spans two separate factor categories, satisfying true multi-factor authentication. Two biometrics, or two passwords, would not qualify as genuine multi-factor.

  • ✓

    Password and smart card

    Why this is correct

    A password is something you know; a smart card is something you have. Combining them draws on two distinct authentication factor categories, satisfying true multi-factor authentication. Two passwords, or a password plus a PIN, would remain single-factor because both are knowledge-based.

  • ✗

    Fingerprint and retina scan

    Why it's wrong here

    Both fingerprint and retina scan verify the same factor — inherence — so this is single-factor authentication, not MFA. It tempts because biometrics feel advanced and secure, and pairing two of them appears to add strength; biometrics are correctly used as one factor alongside a password or token.

  • ✗

    Password and PIN

    Why it's wrong here

    A password and a PIN are both knowledge factors, so combining them remains single-factor authentication regardless of how many prompts appear. It tempts because two separate secrets feel like added security, but true MFA requires different factor categories, such as knowledge plus possession or inherence.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.