Courseiva
Identity and Access ManagementmediumMultiple ChoiceObjective-mapped

CISSP Identity and Access Management Practice Question

A security architect is designing an authentication system for a healthcare application that requires strong security. The system will use a password and a one-time passcode sent via SMS. How many authentication factor types are being used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Two

Password is Type 1 (something you know), SMS OTP is Type 2 (something you have, as the phone is possessed). Only two factor types are used.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Three

    Why it's wrong here

    This option is incorrect because the authentication system described utilizes only two distinct factor types, not three. The primary categories of authentication factors are 'something you know' (knowledge), 'something you have' (possession), and 'something you are' (inherence, e.g., biometrics). The scenario involves a password (knowledge) and an SMS OTP (possession), clearly indicating the absence of a third, distinct factor like a fingerprint scan or retinal pattern.

  • Four

    Why it's wrong here

    This option is incorrect as the system employs only two distinct authentication factor types. While advanced authentication systems might incorporate additional contextual elements such as location or time, these are generally considered attributes for adaptive authentication or risk-based analysis rather than fundamental, independent authentication factors in the same vein as knowledge, possession, or inherence. Therefore, counting four distinct factors is not applicable to the given scenario.

  • One

    Why it's wrong here

    This option is incorrect because the authentication system explicitly combines two different types of factors. Single-factor authentication would rely solely on one type, such as only a password or only an SMS OTP. However, the system requires both a password, which is a 'something you know' factor, and an SMS OTP, which is a 'something you have' factor, thereby clearly exceeding a single factor.

  • Two

    Why this is correct

    This option is correct because the authentication system leverages two distinct types of factors to verify a user's identity. The password serves as the 'something you know' factor, requiring the user to recall a secret piece of information. The SMS One-Time Password (OTP), delivered to a registered mobile device, functions as the 'something you have' factor, relying on the user's possession of that specific device. This combination of two different factor categories precisely defines two-factor authentication (2FA).

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.