Courseiva
Security Principles →easyMultiple Choice

ISC2 CC Security Principles Practice Question

Which authentication type is a smart card an example of?

⚠ Common exam trap

Watch out — candidates often confuse a single authentication factor (possession) with multi-factor authentication, causing candidates to select 'Multi-factor' simply because smart cards are often used in MFA deployments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Type 2 (possession)

A smart card is a physical token that the user must possess, which maps directly to Type 2 authentication (something you have). The three classic authentication factors are Type 1 (something you know, like a password), Type 2 (something you have, like a smart card or token), and Type 3 (something you are, like a fingerprint). Because the smart card is a physical object held by the user, it is the canonical example of possession-based authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Type 1 (knowledge)

    Why it's wrong here

    Type 1 covers knowledge — something you know, such as a password or PIN. A smart card is something you have, classified as Type 2 ownership. Tempting because a card often pairs with a PIN, but the card itself is a possession factor, not knowledge.

  • ✓

    Type 2 (possession)

    Why this is correct

    A smart card is a physical token you must possess and present, making it something you have. That possession factor satisfies the stem's Type 2 constraint, distinguishing it from knowledge (Type 1) and biometric (Type 3) authentication.

  • ✗

    Type 3 (inherence)

    Why it's wrong here

    Type 3 covers inherence — something you are, such as a fingerprint or retinal pattern. A smart card is something you have, which is Type 2 ownership. It tempts because both are physical, personal authentication factors, but possession and biometric characteristics sit on different authentication axes.

  • ✗

    Multi-factor

    Why it's wrong here

    Multi-factor means combining two or more different factor types, whereas a smart card alone is a single Type 2 ownership factor. It tempts because smart cards frequently participate in multi-factor schemes alongside a PIN, but the card in isolation is not itself multi-factor authentication.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.