ISC2 CC Security Principles Practice Question
A security analyst is designing a multi-factor authentication system for remote access. Which TWO of the following combinations represent true multi-factor authentication? (Select TWO)
⚠ Common exam trap
The trap is that candidates see two different-looking authentication methods and assume MFA, without checking whether both factors belong to the same category (e.g., two biometrics or two knowledge factors).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Fingerprint and password
Option B (fingerprint and password) is correct because it combines a biometric inherence factor (the fingerprint) with a knowledge factor (the password), satisfying true MFA by mixing two different factor categories. Option C (password and smart card) is correct because it pairs a knowledge factor (the password) with a possession factor (the smart card, something you have), which are distinct factor types. Option A (smart card and OTP token) is not true MFA because both are possession factors (something you have), even though they are different technologies. Option D (fingerprint and retina scan) is not true MFA because both are biometric inherence factors (something you are). Option E (password and PIN) is not true MFA because both are knowledge factors (something you know).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Smart card and OTP token
Why it's wrong here
A smart card and an OTP token both satisfy the possession factor, so combining them yields single-factor authentication, not true MFA. It tempts because two separate physical devices appear to strengthen access; a smart card would be correct when paired with a PIN or biometric from a different factor.
- ✓
Fingerprint and password
Why this is correct
A fingerprint is something you are (inherence), while a password is something you know (knowledge). Pairing them spans two separate factor categories, satisfying true multi-factor authentication. Two biometrics, or two passwords, would not qualify as genuine multi-factor.
- ✓
Password and smart card
Why this is correct
A password is something you know; a smart card is something you have. Combining them draws on two distinct authentication factor categories, satisfying true multi-factor authentication. Two passwords, or a password plus a PIN, would remain single-factor because both are knowledge-based.
- ✗
Fingerprint and retina scan
Why it's wrong here
Both fingerprint and retina scan verify the same factor — inherence — so this is single-factor authentication, not MFA. It tempts because biometrics feel advanced and secure, and pairing two of them appears to add strength; biometrics are correctly used as one factor alongside a password or token.
- ✗
Password and PIN
Why it's wrong here
A password and a PIN are both knowledge factors, so combining them remains single-factor authentication regardless of how many prompts appear. It tempts because two separate secrets feel like added security, but true MFA requires different factor categories, such as knowledge plus possession or inherence.
Go deeper
Related to this question
Learn chapter
Wireless and Remote Access Security
Key term
Facial Recognition Technology
Facial recognition technology is a biometric security method that identifies or verifies a person by analyzing and comparing patterns of their facial features.
Key term
Time-based One-time Password
A temporary, automatically generated code that changes every few seconds and is used as an extra layer of security when logging into an account.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.