Courseiva
Security Principles →mediumMultiple Choice

ISC2 CC Security Principles Practice Question

A security professional is asked to choose an authentication method for a high-security facility. The requirement is to use something the user 'is'. Which authentication type should be selected?

⚠ Common exam trap

CC often tests the distinction between authentication factor types (knowledge, possession, inherence) and multi-factor authentication, so candidates may mistakenly choose 'multi-factor authentication' when the question asks for a specific factor type.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Type 3 – Inherence factor

Type 3 – Inherence factor refers to something the user 'is', i.e., a biometric characteristic such as fingerprint, retina, or iris. The requirement explicitly states 'something the user is', which directly maps to inherence. Therefore, Type 3 is the correct authentication type.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Type 3 – Inherence factor

    Why this is correct

    Type 3 authentication verifies something the user is, through inherence factors such as fingerprints, iris patterns or facial geometry. The stem explicitly requires something the user 'is', ruling out Type 1 (knowledge) and Type 2 (ownership) factors. Biometrics therefore satisfy the high-security facility's requirement.

  • ✗

    Multi-factor authentication

    Why it's wrong here

    Multi-factor authentication combines two or more different factor categories; it does not itself denote a biometric. It is tempting because it strengthens assurance and is standard for high-security facilities, and would be correct if the requirement were simply stronger authentication, but the stem specifies something the user is.

  • ✗

    Type 2 – Possession factor

    Why it's wrong here

    A possession factor verifies something the user has, such as a smart card or hardware token, which can be lost, stolen or cloned. It is tempting because tokens pair well with biometrics for high-security access, and would be correct as a second factor, but it is not the something-you-are factor requested.

  • ✗

    Type 1 – Knowledge factor

    Why it's wrong here

    A knowledge factor verifies something the user knows, such as a password or PIN, which an attacker can obtain through phishing or guessing. It is tempting because passwords are cheap and familiar, and would be correct for a low-risk login, but the stem demands a biometric trait.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.