ISC2 CC Access Controls Concepts Practice Question
A user logs into a corporate portal by entering a username and password. The system then prompts for a one-time code from a mobile authenticator app. Which two factors of authentication are being combined in this scenario?
⚠ Common exam trap
The trap here is treating a one-time code as a knowledge factor because the user reads and types it, rather than recognizing it as a possession factor tied to the device.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Something you know and something you have
Multi-factor authentication requires combining factors from different categories. The password is a knowledge factor, and the one-time code from a registered mobile app is a possession factor. Together they form something you know plus something you have. The other pairings involve biometrics or location, neither of which appears in the described login sequence, so they do not accurately describe the factors in use.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Something you know and something you have
Why this is correct
The password represents something the user knows, while the one-time code generated by the mobile authenticator app represents something the user has, namely the registered device. Combining these two distinct factor types satisfies multi-factor authentication. This pairing is the most common MFA implementation and directly matches the scenario's username/password plus app-generated code.
- ✗
Something you know and something you are
Why it's wrong here
Something you are refers to biometrics such as fingerprints or facial recognition. The scenario uses a password and a one-time code from an app, neither of which is a biometric trait. Although biometrics can be a factor, no fingerprint, iris, or facial scan is described here, so this pairing does not match the authentication methods in use.
- ✗
Something you have and something you are
Why it's wrong here
This pairing combines a possession factor with a biometric factor. The scenario does include a possession factor, the authenticator app, but it uses a password rather than a biometric. Because no physical characteristic of the user is checked, this combination is incorrect for the described login process.
- ✗
Something you know and somewhere you are
Why it's wrong here
Location is sometimes treated as a contextual attribute, but it is not one of the three classic authentication factors. The scenario does not evaluate the user's geographic position. It relies on a password and a one-time code, so the location-based pairing does not describe the factors actually being combined.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
Biometrics
Biometrics is the technology that uses unique physical or behavioral traits, like fingerprints or voice patterns, to verify a person's identity.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.