Courseiva
Identity and Access ManagementeasyMultiple ChoiceObjective-mapped

CISSP Identity and Access Management Practice Question

Which of the following is an example of a Type 2 authentication factor?

⚠ Common exam trap

Test-takers frequently confuse a smart card with a PIN or password because both are used together in practice, but the question specifically asks for the factor type of the smart card itself, not the combined authentication method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Smart card

A smart card is a Type 2 authentication factor because it falls under the category of 'something you have.' Type 2 factors are possession-based, meaning the user must physically possess the token to authenticate. Smart cards store cryptographic keys or certificates and require a card reader to present the credential, making them a classic example of a possession factor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Smart card

    Why this is correct

    A smart card represents 'something you have' (Type 2) because it is a physical token that must be possessed by the user to grant access. These cards typically contain an embedded microchip capable of performing cryptographic operations, such as storing digital certificates or generating one-time passwords. Its security relies on the physical control of the device, making it a robust authentication factor, often combined with a PIN for multi-factor authentication.

  • PIN

    Why it's wrong here

    A Personal Identification Number (PIN) is classified as 'something you know' (Type 1) because it is a secret numerical code that the user must recall from memory to authenticate. Unlike physical tokens, a PIN's security is entirely dependent on its secrecy and the user's ability to keep it confidential. It offers a relatively low level of assurance when used in isolation, as it can be susceptible to guessing, brute-force attacks, or shoulder surfing.

  • Password

    Why it's wrong here

    A password is a classic example of 'something you know' (Type 1), functioning as a secret string of characters that a user must memorize and input to prove their identity. Its effectiveness as an authentication factor is directly tied to its complexity, uniqueness, and the user's ability to keep it private. Passwords alone are vulnerable to various attacks, including dictionary attacks, brute-force attempts, and phishing, highlighting the need for stronger authentication methods.

  • Fingerprint

    Why it's wrong here

    A fingerprint is categorized as 'something you are' (Type 3) because it leverages a unique biological characteristic inherent to an individual for authentication. This biometric factor involves scanning and matching the distinct patterns of ridges and valleys on a user's finger against a stored template. While convenient and difficult to forge perfectly, biometric systems can be susceptible to presentation attacks (spoofing) and raise privacy concerns regarding the storage and use of immutable personal data.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.