ISC2 CC Security Principles Practice Question
Which TWO of the following are examples of multi-factor authentication? (Select TWO.)
⚠ Common exam trap
Watch out — candidates often assume any two authentication methods constitute MFA, but the methods must belong to different factor categories (knowledge, possession, inherence).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Password and SMS one-time code
Option B (Password and SMS one-time code) is correct because it combines two different authentication factor categories: something you know (the password) and something you have (the SMS one-time code delivered to your phone), which is the definition of multi-factor authentication. Option C (Biometric and PIN) is correct because it pairs something you are (the biometric, such as a fingerprint) with something you know (the PIN), satisfying the requirement for multiple distinct factor types. Option A is not multi-factor because a smart card and an RSA token are both something you have, so they belong to the same factor category. Option D is not multi-factor because a fingerprint and a retina scan are both inherence factors (something you are). Option E is not multi-factor because a password and a security question are both knowledge factors (something you know).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Smart card and RSA token
Why it's wrong here
A smart card and an RSA token are both possession factors, so pairing them remains single-factor authentication. It tempts because hardware tokens appear robust, but multi-factor requires distinct categories, such as a possession factor combined with a knowledge or inherence factor.
- ✓
Password and SMS one-time code
Why this is correct
A password is something you know, while an SMS one-time code is delivered to something you possess, the enrolled phone. Combining two distinct factor categories satisfies multi-factor authentication, whereas two passwords or two possession tokens would not.
- ✓
Biometric and PIN
Why this is correct
A biometric is something you are, while a PIN is something you know. Pairing these two distinct factor categories satisfies multi-factor authentication, whereas two knowledge factors or two biometrics would remain single-category and fail the stem's requirement.
- ✗
Fingerprint and retina scan
Why it's wrong here
Fingerprint and retina scan are both inherence factors, so combining them still yields single-factor authentication. It tempts because biometrics feel strong, yet multi-factor demands two different categories — something you know, have, or are — and this option supplies only one.
- ✗
Password and security question
Why it's wrong here
A password and a security question are both knowledge factors, so this pairing is single-factor authentication. It tempts because two prompts feel like layered security, yet multi-factor demands different categories — knowledge plus possession or inherence — not two variations of the same category.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Time-based One-time Password
A temporary, automatically generated code that changes every few seconds and is used as an extra layer of security when logging into an account.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.