ISC2 CC Security Principles Practice Question
An organization implements a policy requiring employees to use a smart card and a PIN to access the data center. This is an example of which type of authentication?
⚠ Common exam trap
Candidates often confuse authentication factor types with authentication methods; candidates often think that a smart card and PIN together are still single-factor because they are both used in one process, but the key is that they represent different factor categories (possession and knowledge).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Multi-factor authentication
Multi-factor authentication (MFA) requires two or more different authentication factors: something you have (smart card), something you know (PIN), and optionally something you are (biometric). Here, the smart card is a possession factor and the PIN is a knowledge factor, so combining them satisfies MFA. This is the correct classification because the two factors are of different types, not just two instances of the same type.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Multi-factor authentication
Why this is correct
The smart card supplies a possession factor and the PIN supplies a knowledge factor, so two distinct factor types are combined. That combination satisfies the definition of multi-factor authentication rather than single-factor or same-category authentication.
- ✗
Type 3 authentication
Why it's wrong here
Type 3 authentication covers something you are — biometrics such as fingerprints or retinal scans — which a smart card and PIN do not involve. It is tempting because factor numbering is easily confused, and Type 3 would be correct if the scenario required a biometric characteristic.
- ✗
Single-factor authentication
Why it's wrong here
A smart card plus a PIN combines something you have with something you know, which is two factors, not one. It is tempting because the PIN alone resembles a password, so the pairing is easily miscounted; single-factor would be correct if only the PIN were required.
- ✗
Type 2 authentication only
Why it's wrong here
A smart card plus PIN combines something you have with something you know, so it satisfies Type 2 (possessed token) and Type 1 (knowledge) simultaneously. The option captures only the token half, ignoring the PIN. Type 2 alone describes a badge swipe without any PIN entry.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.