CISSP Identity and Access Management Practice Question
A security architect is designing an authentication system for a healthcare application that requires strong security. The system will use a password and a one-time passcode sent via SMS. How many authentication factor types are being used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Two
Password is Type 1 (something you know), SMS OTP is Type 2 (something you have, as the phone is possessed). Only two factor types are used.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Three
Why it's wrong here
This option is incorrect because the authentication system described utilizes only two distinct factor types, not three. The primary categories of authentication factors are 'something you know' (knowledge), 'something you have' (possession), and 'something you are' (inherence, e.g., biometrics). The scenario involves a password (knowledge) and an SMS OTP (possession), clearly indicating the absence of a third, distinct factor like a fingerprint scan or retinal pattern.
- ✗
Four
Why it's wrong here
This option is incorrect as the system employs only two distinct authentication factor types. While advanced authentication systems might incorporate additional contextual elements such as location or time, these are generally considered attributes for adaptive authentication or risk-based analysis rather than fundamental, independent authentication factors in the same vein as knowledge, possession, or inherence. Therefore, counting four distinct factors is not applicable to the given scenario.
- ✗
One
Why it's wrong here
This option is incorrect because the authentication system explicitly combines two different types of factors. Single-factor authentication would rely solely on one type, such as only a password or only an SMS OTP. However, the system requires both a password, which is a 'something you know' factor, and an SMS OTP, which is a 'something you have' factor, thereby clearly exceeding a single factor.
- ✓
Two
Why this is correct
This option is correct because the authentication system leverages two distinct types of factors to verify a user's identity. The password serves as the 'something you know' factor, requiring the user to recall a secret piece of information. The SMS One-Time Password (OTP), delivered to a registered mobile device, functions as the 'something you have' factor, relying on the user's possession of that specific device. This combination of two different factor categories precisely defines two-factor authentication (2FA).
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.