ISC2 CC Security Principles Practice Question
Which TWO of the following are examples of Type 3 (inherence) authentication factors?
⚠ Common exam trap
CC often tests the confusion between possession factors (smart card, token) and inherence factors (biometrics), so candidates might incorrectly select OTP token or smart card as inherence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Retina scan
Type 3 (inherence) authentication factors are based on something the user is — a physical or behavioral biometric characteristic of the individual. Option C, retina scan, is correct because it measures the unique pattern of blood vessels in the user's retina, an inherent physiological trait that cannot be transferred or forgotten. Option E, fingerprint scan, is correct because it reads the distinct ridge and minutiae pattern of the user's finger, another inborn biometric attribute. The remaining options do not belong: A (OTP token) and B (smart card) are Type 2 (possession) factors — something the user has — while D (password) is a Type 1 (knowledge) factor — something the user knows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
OTP token
Why it's wrong here
An OTP token is a possession factor (Type 2): the user must physically hold the device generating the code. Inherence requires a biological or behavioural characteristic of the person, such as a fingerprint or typing rhythm. It is tempting because tokens are something the user 'has', which feels intrinsic, but ownership is not inherence.
- ✗
Smart card
Why it's wrong here
A smart card is a Type 2 possession factor — something the user has — not inherence. It is tempting because it is a physical token tied to an individual, but inherence demands a biometric characteristic of the body, such as a fingerprint or retinal pattern, rather than a carried device.
- ✓
Retina scan
Why this is correct
A retina scan measures a physiological characteristic of the user's body, which is inherent and therefore a Type 3 inherence factor. It is not something the user knows or possesses, so it satisfies the requirement for an inherence-based example.
- ✗
Password
Why it's wrong here
A password is a Type 1 knowledge factor — something the user knows — not inherence. It is tempting because passwords are the most familiar authentication method, yet inherence requires a biometric trait such as a fingerprint, iris pattern or voiceprint that is physically part of the user.
- ✓
Fingerprint scan
Why this is correct
A fingerprint scan reads a unique physical trait of the user, making it an inherence factor under Type 3. Because the characteristic is intrinsic to the person rather than memorised or carried, it meets the question's requirement for a Type 3 example.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Common Access Card
A Common Access Card (CAC) is a smart card issued by the U.S. Department of Defense that serves as a single identification, authentication, and access credential for military personnel and contractors.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.