Courseiva
Security Principles →mediumMultiple Choice

ISC2 CC Security Principles Practice Question

An organization implements a policy requiring employees to use a smart card and a PIN to access the data center. This is an example of which type of authentication?

⚠ Common exam trap

Candidates often confuse authentication factor types with authentication methods; candidates often think that a smart card and PIN together are still single-factor because they are both used in one process, but the key is that they represent different factor categories (possession and knowledge).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multi-factor authentication

Multi-factor authentication (MFA) requires two or more different authentication factors: something you have (smart card), something you know (PIN), and optionally something you are (biometric). Here, the smart card is a possession factor and the PIN is a knowledge factor, so combining them satisfies MFA. This is the correct classification because the two factors are of different types, not just two instances of the same type.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Multi-factor authentication

    Why this is correct

    The smart card supplies a possession factor and the PIN supplies a knowledge factor, so two distinct factor types are combined. That combination satisfies the definition of multi-factor authentication rather than single-factor or same-category authentication.

  • ✗

    Type 3 authentication

    Why it's wrong here

    Type 3 authentication covers something you are — biometrics such as fingerprints or retinal scans — which a smart card and PIN do not involve. It is tempting because factor numbering is easily confused, and Type 3 would be correct if the scenario required a biometric characteristic.

  • ✗

    Single-factor authentication

    Why it's wrong here

    A smart card plus a PIN combines something you have with something you know, which is two factors, not one. It is tempting because the PIN alone resembles a password, so the pairing is easily miscounted; single-factor would be correct if only the PIN were required.

  • ✗

    Type 2 authentication only

    Why it's wrong here

    A smart card plus PIN combines something you have with something you know, so it satisfies Type 2 (possessed token) and Type 1 (knowledge) simultaneously. The option captures only the token half, ignoring the PIN. Type 2 alone describes a badge swipe without any PIN entry.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.