CISSP Identity and Access Management Practice Question
Which of the following is an example of a Type 1 authentication factor?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Password
A Type 1 factor is something you know, such as a password, PIN, or security question.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
OTP token
Why it's wrong here
An OTP (One-Time Password) token represents a Type 2 authentication factor, categorized as "something you have." This physical or software-based device generates a unique, time-sensitive numerical or alphanumeric code that is valid for only a single login session or transaction. Its effectiveness stems from the requirement for physical possession of the token, making it a robust second factor in multi-factor authentication schemes. Without the token, an attacker cannot generate the correct, ephemeral credential.
- ✗
Fingerprint
Why it's wrong here
A fingerprint is a prime example of a Type 3 authentication factor, often referred to as "something you are." This category relies on unique, inherent biological or physiological characteristics of an individual, which are extremely difficult to replicate or transfer. Biometric authentication systems capture and compare these immutable physical traits, such as ridge patterns, to verify identity, providing a highly personal and non-transferable form of proof. Its strength lies in its intrinsic link to the user's physical self.
- ✓
Password
Why this is correct
A password serves as a classic example of a Type 1 authentication factor, representing "something you know." This form of authentication relies on a secret piece of information, such as a string of characters, that only the legitimate user is supposed to possess and recall. Users must cognitively remember and accurately input this credential to prove their identity, making it a foundational element in most access control systems. Its security is directly dependent on its complexity and the user's ability to keep it confidential.
- ✗
Smart card
Why it's wrong here
A smart card functions as a Type 2 authentication factor, falling under the "something you have" category. This small, portable device typically contains an embedded integrated circuit chip capable of storing cryptographic keys, digital certificates, and other sensitive credentials securely. When inserted into a reader, the smart card performs cryptographic operations to authenticate the user, proving possession of the physical token and the associated digital identity. Its security is derived from the tamper-resistant nature of the chip and the requirement for its physical presence.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.