SSCP Access Controls Practice Question
A small business wants employees to authenticate to the corporate VPN using a hardware token that generates a time-based one-time code in addition to their password. Which authentication factor category does the hardware token represent?
⚠ Common exam trap
The trap here is counting two credentials from the same category, such as a password plus a security question, as multi-factor authentication when only a single factor category is actually present.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Something you have
Authentication factors fall into categories including knowledge, possession, inherence, and location. A hardware token that generates time-based one-time codes must be physically held by the user, making it a possession factor. Pairing it with a password, which is a knowledge factor, satisfies multi-factor authentication because two different categories are required, rather than two instances of the same category.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Something you are
Why it's wrong here
Something you are refers to biometric characteristics such as fingerprints, iris patterns, or voiceprints. The described hardware token produces one-time codes rather than measuring a physical trait of the user, so it does not belong in the inherence category. Confusing possession tokens with biometrics is a common error that would misclassify the authentication assurance this solution provides.
- ✗
Something you know
Why it's wrong here
Something you know refers to knowledge-based factors such as a password, PIN, or passphrase. In this scenario the password already satisfies that category; the hardware token generating a time-based code is a separate factor. Treating the token as something you know would collapse two distinct factors into one category and undermine the strength of the multi-factor authentication being deployed.
- ✓
Something you have
Why this is correct
A hardware token that generates time-based one-time codes is a possession factor, meaning the user must physically hold the device to authenticate. Combined with a password, which is a knowledge factor, this creates true multi-factor authentication because it draws on two different categories. The possession factor is exactly what the token contributes in this VPN scenario.
- ✗
Somewhere you are
Why it's wrong here
Somewhere you are describes location-based factors such as source IP geolocation or proximity to a known network. The hardware token in this scenario authenticates the user regardless of where the VPN connection originates, so location is not the factor being demonstrated. Assigning the token to this category would misrepresent how the authentication actually works.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.