ISC2 CC Security Principles Practice Question
Which type of authentication factor involves something the user knows?
⚠ Common exam trap
It's easy for candidates to confuse Type 2 (possession) with Type 1 (knowledge) — candidates often assume 'something you have' is the most common factor, but the question explicitly asks for 'something you know.'
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Type 1 (knowledge)
Type 1 authentication is 'something you know' — knowledge factors such as passwords, PINs, or security questions. This is the classic knowledge-based factor and is correctly identified as Type 1 in the standard authentication factor taxonomy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Type 1 (knowledge)
Why this is correct
Type 1 factors are knowledge-based, covering passwords, PINs and passphrases that a user memorises. This matches the stem's requirement for something the user knows, distinguishing it from Type 2 (something possessed) and Type 3 (something inherent).
- ✗
Type 2 (possession)
Why it's wrong here
Possession is Type 2, covering something you have, such as a token or smart card, so it cannot represent a remembered secret. It tempts because possession factors are the standard second factor in MFA, correct when the requirement is proving control of a physical or software token.
- ✗
Type 4 (location)
Why it's wrong here
Location is Type 4, covering somewhere you are, such as source IP or geolocation, so it cannot represent a remembered secret. It tempts because location checks are genuinely used as a contextual authentication signal, correct when policy must restrict access by geography rather than verify knowledge.
- ✗
Type 3 (inherence)
Why it's wrong here
Inherence is Type 3, covering something you are, such as a fingerprint or facial geometry, so it cannot represent a remembered secret. It tempts because biometrics are widely deployed for strong authentication, correct when the requirement is verifying a physical characteristic rather than knowledge.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.