Courseiva
Identity and Access ManagementeasyMultiple ChoiceObjective-mapped

CISSP Identity and Access Management Practice Question

Which of the following is an example of a Type 1 authentication factor?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Password

A Type 1 factor is something you know, such as a password, PIN, or security question.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • OTP token

    Why it's wrong here

    An OTP (One-Time Password) token represents a Type 2 authentication factor, categorized as "something you have." This physical or software-based device generates a unique, time-sensitive numerical or alphanumeric code that is valid for only a single login session or transaction. Its effectiveness stems from the requirement for physical possession of the token, making it a robust second factor in multi-factor authentication schemes. Without the token, an attacker cannot generate the correct, ephemeral credential.

  • Fingerprint

    Why it's wrong here

    A fingerprint is a prime example of a Type 3 authentication factor, often referred to as "something you are." This category relies on unique, inherent biological or physiological characteristics of an individual, which are extremely difficult to replicate or transfer. Biometric authentication systems capture and compare these immutable physical traits, such as ridge patterns, to verify identity, providing a highly personal and non-transferable form of proof. Its strength lies in its intrinsic link to the user's physical self.

  • Password

    Why this is correct

    A password serves as a classic example of a Type 1 authentication factor, representing "something you know." This form of authentication relies on a secret piece of information, such as a string of characters, that only the legitimate user is supposed to possess and recall. Users must cognitively remember and accurately input this credential to prove their identity, making it a foundational element in most access control systems. Its security is directly dependent on its complexity and the user's ability to keep it confidential.

  • Smart card

    Why it's wrong here

    A smart card functions as a Type 2 authentication factor, falling under the "something you have" category. This small, portable device typically contains an embedded integrated circuit chip capable of storing cryptographic keys, digital certificates, and other sensitive credentials securely. When inserted into a reader, the smart card performs cryptographic operations to authenticate the user, proving possession of the physical token and the associated digital identity. Its security is derived from the tamper-resistant nature of the chip and the requirement for its physical presence.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.