Courseiva
Identity and Access ManagementmediumMultiple ChoiceObjective-mapped

CISSP Identity and Access Management Practice Question

A security administrator is configuring a system that requires users to provide a password and a one-time code from a hardware token. Which authentication method is being implemented?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Multi-factor authentication

Using two different factor types (password and hardware token) constitutes multi-factor authentication (MFA).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Biometric authentication

    Why it's wrong here

    Biometric authentication refers to a specific type of authentication factor, 'something you are,' such as a fingerprint or facial scan. While it can be a component of a robust multi-factor authentication scheme, it does not describe the overarching requirement for combining multiple *different* types of factors for system access. The question implies a broader requirement for multiple factor types, not just the use of a biometric factor in isolation or as the sole additional factor.

  • Step-up authentication

    Why it's wrong here

    Step-up authentication is a security mechanism that demands additional or stronger authentication factors only when a user attempts to access particularly sensitive resources or perform high-risk operations *after* their initial login. It is a conditional process that enhances security for specific actions, rather than defining the standard, initial login method that combines different factor types from the outset. Therefore, it does not describe the fundamental requirement for a system configured to use multiple factors for every login attempt.

  • Single-factor authentication

    Why it's wrong here

    Single-factor authentication (SFA) relies on only one category of authentication credential, such as a password (something you know) or a smart card (something you have), to verify a user's identity. This method provides a lower level of security as it presents a single point of failure for attackers to target. The question explicitly indicates that two distinct authentication factor types are employed, directly contradicting the definition of SFA.

  • Multi-factor authentication

    Why this is correct

    Multi-factor authentication (MFA) is the correct choice because it precisely describes an authentication system that requires a user to present two or more independent authentication factors from different categories to verify their identity. By combining distinct types, such as 'something you know' (e.g., a password) and 'something you have' (e.g., a token or smart card), MFA significantly enhances security. This approach ensures that even if one factor is compromised, unauthorized access is prevented due to the requirement for a second, different factor.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.