Courseiva
Security Principles →mediumMultiple Select

ISC2 CC Security Principles Practice Question

Which TWO of the following are examples of multi-factor authentication? (Select TWO.)

⚠ Common exam trap

Watch out — candidates often assume any two authentication methods constitute MFA, but the methods must belong to different factor categories (knowledge, possession, inherence).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Password and SMS one-time code

Option B (Password and SMS one-time code) is correct because it combines two different authentication factor categories: something you know (the password) and something you have (the SMS one-time code delivered to your phone), which is the definition of multi-factor authentication. Option C (Biometric and PIN) is correct because it pairs something you are (the biometric, such as a fingerprint) with something you know (the PIN), satisfying the requirement for multiple distinct factor types. Option A is not multi-factor because a smart card and an RSA token are both something you have, so they belong to the same factor category. Option D is not multi-factor because a fingerprint and a retina scan are both inherence factors (something you are). Option E is not multi-factor because a password and a security question are both knowledge factors (something you know).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Smart card and RSA token

    Why it's wrong here

    A smart card and an RSA token are both possession factors, so pairing them remains single-factor authentication. It tempts because hardware tokens appear robust, but multi-factor requires distinct categories, such as a possession factor combined with a knowledge or inherence factor.

  • ✓

    Password and SMS one-time code

    Why this is correct

    A password is something you know, while an SMS one-time code is delivered to something you possess, the enrolled phone. Combining two distinct factor categories satisfies multi-factor authentication, whereas two passwords or two possession tokens would not.

  • ✓

    Biometric and PIN

    Why this is correct

    A biometric is something you are, while a PIN is something you know. Pairing these two distinct factor categories satisfies multi-factor authentication, whereas two knowledge factors or two biometrics would remain single-category and fail the stem's requirement.

  • ✗

    Fingerprint and retina scan

    Why it's wrong here

    Fingerprint and retina scan are both inherence factors, so combining them still yields single-factor authentication. It tempts because biometrics feel strong, yet multi-factor demands two different categories — something you know, have, or are — and this option supplies only one.

  • ✗

    Password and security question

    Why it's wrong here

    A password and a security question are both knowledge factors, so this pairing is single-factor authentication. It tempts because two prompts feel like layered security, yet multi-factor demands different categories — knowledge plus possession or inherence — not two variations of the same category.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.