Courseiva
Security Principles →mediumMultiple Choice

ISC2 CC Multi-factor authentication (MFA) Practice Question

When implementing multi-factor authentication, which combination of factors is considered strongest?

⚠ Common exam trap

The trap is that candidates may think any two authentication methods constitute MFA, but the exam tests whether they recognize that factors must come from different categories, so combinations like password and PIN are not true MFA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Smart card and biometric

Multi-factor authentication (MFA) requires combining factors from different categories: something you know (password, PIN), something you have (smart card, token), and something you are (biometric). The strongest combination uses factors from separate categories, such as a smart card (something you have) and a biometric (something you are). This provides defense in depth because compromising one factor does not compromise the other.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Password and PIN

    Why it's wrong here

    A PIN is memorised, so it belongs to the same 'something you know' category as the password, giving two instances of one factor rather than genuine multi-factor authentication. It is tempting because PINs are simple to issue, and this pairing would be acceptable only where policy defines a password plus PIN as two distinct authentication elements.

  • ✗

    Password and security question

    Why it's wrong here

    A security question is a knowledge-based factor, so it shares the 'something you know' category with the password rather than adding a distinct factor type. It is tempting because knowledge-based authentication is easy to deploy, and it would satisfy MFA only where no stronger second factor, such as a hardware token or biometric, is available.

  • ✓

    Smart card and biometric

    Why this is correct

    A smart card is a possession factor and a biometric is an inherence factor, so pairing them combines two genuinely different factor categories. This is stronger than combining two knowledge factors or a knowledge factor with a possession factor, satisfying the requirement for the strongest combination.

  • ✗

    Biometric and fingerprint

    Why it's wrong here

    Fingerprint and biometric are both inherence factors, so combining them yields a single factor category and no true multi-factor strength. This pairing would satisfy a liveness or anti-spoofing check within one factor. Genuine MFA requires different categories, such as something you know plus something you have.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.