CISSP Identity and Access Management Practice Question
A security administrator is configuring a system that requires users to provide a password and a one-time code from a hardware token. Which authentication method is being implemented?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Multi-factor authentication
Using two different factor types (password and hardware token) constitutes multi-factor authentication (MFA).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Biometric authentication
Why it's wrong here
Biometric authentication refers to a specific type of authentication factor, 'something you are,' such as a fingerprint or facial scan. While it can be a component of a robust multi-factor authentication scheme, it does not describe the overarching requirement for combining multiple *different* types of factors for system access. The question implies a broader requirement for multiple factor types, not just the use of a biometric factor in isolation or as the sole additional factor.
- ✗
Step-up authentication
Why it's wrong here
Step-up authentication is a security mechanism that demands additional or stronger authentication factors only when a user attempts to access particularly sensitive resources or perform high-risk operations *after* their initial login. It is a conditional process that enhances security for specific actions, rather than defining the standard, initial login method that combines different factor types from the outset. Therefore, it does not describe the fundamental requirement for a system configured to use multiple factors for every login attempt.
- ✗
Single-factor authentication
Why it's wrong here
Single-factor authentication (SFA) relies on only one category of authentication credential, such as a password (something you know) or a smart card (something you have), to verify a user's identity. This method provides a lower level of security as it presents a single point of failure for attackers to target. The question explicitly indicates that two distinct authentication factor types are employed, directly contradicting the definition of SFA.
- ✓
Multi-factor authentication
Why this is correct
Multi-factor authentication (MFA) is the correct choice because it precisely describes an authentication system that requires a user to present two or more independent authentication factors from different categories to verify their identity. By combining distinct types, such as 'something you know' (e.g., a password) and 'something you have' (e.g., a token or smart card), MFA significantly enhances security. This approach ensures that even if one factor is compromised, unauthorized access is prevented due to the requirement for a second, different factor.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.