ISC2 CC Security Principles Practice Question
Which authentication type is a smart card an example of?
⚠ Common exam trap
Watch out — candidates often confuse a single authentication factor (possession) with multi-factor authentication, causing candidates to select 'Multi-factor' simply because smart cards are often used in MFA deployments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Type 2 (possession)
A smart card is a physical token that the user must possess, which maps directly to Type 2 authentication (something you have). The three classic authentication factors are Type 1 (something you know, like a password), Type 2 (something you have, like a smart card or token), and Type 3 (something you are, like a fingerprint). Because the smart card is a physical object held by the user, it is the canonical example of possession-based authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Type 1 (knowledge)
Why it's wrong here
Type 1 covers knowledge — something you know, such as a password or PIN. A smart card is something you have, classified as Type 2 ownership. Tempting because a card often pairs with a PIN, but the card itself is a possession factor, not knowledge.
- ✓
Type 2 (possession)
Why this is correct
A smart card is a physical token you must possess and present, making it something you have. That possession factor satisfies the stem's Type 2 constraint, distinguishing it from knowledge (Type 1) and biometric (Type 3) authentication.
- ✗
Type 3 (inherence)
Why it's wrong here
Type 3 covers inherence — something you are, such as a fingerprint or retinal pattern. A smart card is something you have, which is Type 2 ownership. It tempts because both are physical, personal authentication factors, but possession and biometric characteristics sit on different authentication axes.
- ✗
Multi-factor
Why it's wrong here
Multi-factor means combining two or more different factor types, whereas a smart card alone is a single Type 2 ownership factor. It tempts because smart cards frequently participate in multi-factor schemes alongside a PIN, but the card in isolation is not itself multi-factor authentication.
Go deeper
Related to this question
Learn chapter
Physical Access Controls
Key term
Multifactor Authentication
Multifactor Authentication (MFA) is a security method that requires you to provide two or more pieces of evidence to prove your identity before accessing an account or system.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.