Courseiva
Security Principles →mediumMultiple Choice

ISC2 CC Security Principles Practice Question

Which of the following is an example of a Type 1 authentication factor?

⚠ Common exam trap

It's easy for candidates to confuse authentication factor types: candidates often mistake a PIN for a possession factor because it's used with a card, but it's actually a knowledge factor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PIN code

A Type 1 authentication factor is something you know, such as a password, PIN, or passphrase. A PIN code is a memorized secret, so it is a classic example of a knowledge-based factor. The other options represent different factor types: OTP token and smart card are something you have (Type 2), and fingerprint scan is something you are (Type 3).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    One-time password (OTP) token

    Why it's wrong here

    An OTP token is a Type 2 factor, something you have, because generating the code depends on possessing the device or token. Type 1 is something you know, such as a password or PIN. OTPs are tempting because the user recalls nothing, yet the factor is the physical token, not memorised knowledge.

  • ✓

    PIN code

    Why this is correct

    A PIN code is something you know, which is the defining characteristic of a Type 1 authentication factor. Type 1 factors rely on knowledge, distinguishing them from Type 2 (possession) and Type 3 (inherence) factors.

  • ✗

    Smart card

    Why it's wrong here

    A smart card is a Type 2 factor, something you have, since possession of the physical card is what is verified. Type 1 is something you know, such as a password or PIN. Smart cards are tempting because they are commonly paired with a PIN, but the card itself satisfies the possession category, not knowledge.

  • ✗

    Fingerprint scan

    Why it's wrong here

    A fingerprint scan is a Type 3 factor, something you are, verified through a biometric characteristic. Type 1 is something you know, such as a password or PIN. Fingerprints are tempting because they authenticate a person strongly, but biometrics belong to the inherence category, not the knowledge category.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.