ISC2 CC Multi-factor authentication (MFA) Practice Question
When implementing multi-factor authentication, which combination of factors is considered strongest?
⚠ Common exam trap
The trap is that candidates may think any two authentication methods constitute MFA, but the exam tests whether they recognize that factors must come from different categories, so combinations like password and PIN are not true MFA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Smart card and biometric
Multi-factor authentication (MFA) requires combining factors from different categories: something you know (password, PIN), something you have (smart card, token), and something you are (biometric). The strongest combination uses factors from separate categories, such as a smart card (something you have) and a biometric (something you are). This provides defense in depth because compromising one factor does not compromise the other.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Password and PIN
Why it's wrong here
A PIN is memorised, so it belongs to the same 'something you know' category as the password, giving two instances of one factor rather than genuine multi-factor authentication. It is tempting because PINs are simple to issue, and this pairing would be acceptable only where policy defines a password plus PIN as two distinct authentication elements.
- ✗
Password and security question
Why it's wrong here
A security question is a knowledge-based factor, so it shares the 'something you know' category with the password rather than adding a distinct factor type. It is tempting because knowledge-based authentication is easy to deploy, and it would satisfy MFA only where no stronger second factor, such as a hardware token or biometric, is available.
- ✓
Smart card and biometric
Why this is correct
A smart card is a possession factor and a biometric is an inherence factor, so pairing them combines two genuinely different factor categories. This is stronger than combining two knowledge factors or a knowledge factor with a possession factor, satisfying the requirement for the strongest combination.
- ✗
Biometric and fingerprint
Why it's wrong here
Fingerprint and biometric are both inherence factors, so combining them yields a single factor category and no true multi-factor strength. This pairing would satisfy a liveness or anti-spoofing check within one factor. Genuine MFA requires different categories, such as something you know plus something you have.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
Key term
Common Access Card
A Common Access Card (CAC) is a smart card issued by the U.S. Department of Defense that serves as a single identification, authentication, and access credential for military personnel and contractors.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.