CISSP Identity and Access Management Practice Question
Which of the following is an example of a Type 2 authentication factor?
⚠ Common exam trap
Test-takers frequently confuse a smart card with a PIN or password because both are used together in practice, but the question specifically asks for the factor type of the smart card itself, not the combined authentication method.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Smart card
A smart card is a Type 2 authentication factor because it falls under the category of 'something you have.' Type 2 factors are possession-based, meaning the user must physically possess the token to authenticate. Smart cards store cryptographic keys or certificates and require a card reader to present the credential, making them a classic example of a possession factor.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Smart card
Why this is correct
A smart card represents 'something you have' (Type 2) because it is a physical token that must be possessed by the user to grant access. These cards typically contain an embedded microchip capable of performing cryptographic operations, such as storing digital certificates or generating one-time passwords. Its security relies on the physical control of the device, making it a robust authentication factor, often combined with a PIN for multi-factor authentication.
- ✗
PIN
Why it's wrong here
A Personal Identification Number (PIN) is classified as 'something you know' (Type 1) because it is a secret numerical code that the user must recall from memory to authenticate. Unlike physical tokens, a PIN's security is entirely dependent on its secrecy and the user's ability to keep it confidential. It offers a relatively low level of assurance when used in isolation, as it can be susceptible to guessing, brute-force attacks, or shoulder surfing.
- ✗
Password
Why it's wrong here
A password is a classic example of 'something you know' (Type 1), functioning as a secret string of characters that a user must memorize and input to prove their identity. Its effectiveness as an authentication factor is directly tied to its complexity, uniqueness, and the user's ability to keep it private. Passwords alone are vulnerable to various attacks, including dictionary attacks, brute-force attempts, and phishing, highlighting the need for stronger authentication methods.
- ✗
Fingerprint
Why it's wrong here
A fingerprint is categorized as 'something you are' (Type 3) because it leverages a unique biological characteristic inherent to an individual for authentication. This biometric factor involves scanning and matching the distinct patterns of ridges and valleys on a user's finger against a stored template. While convenient and difficult to forge perfectly, biometric systems can be susceptible to presentation attacks (spoofing) and raise privacy concerns regarding the storage and use of immutable personal data.
Go deeper
Related to this question
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.