Multi-Factor Authentication: Examples of Different Factors
An organization wants to implement multi-factor authentication (MFA) for remote access. Which combination represents something you have and something you are?
⚠ Common exam trap
SSCP often tests factor-category confusion — candidates see two credentials and assume MFA, missing that both must come from different categories (know, have, are).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Smart card and fingerprint
A smart card is a physical token the user possesses (something you have), and a fingerprint is a biometric trait inherent to the user (something you are). Combining them satisfies the requirement for two different MFA factor categories. This is a classic possession-plus-inherence pairing used in high-assurance environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Password and security question
Why it's wrong here
Both a password and a security question are knowledge factors, so this is single-factor authentication repeated, not MFA. It tempts because security questions appear as a second prompt, but they test recall rather than possession or inherence, so they add no distinct factor category.
- ✗
Smart card and PIN
Why it's wrong here
A smart card is something you have, but a PIN is something you know, so this pairs possession with knowledge rather than inherence. It is tempting because smart card plus PIN is a classic strong two-factor scheme, yet the question requires something you are, satisfied only by a biometric such as a fingerprint.
- ✗
Password and one-time passcode (OTP)
Why it's wrong here
A password is something you know and an OTP is also something you know or possess temporarily, so both factors sit in knowledge or possession, not inherence. This pairing is common because it delivers MFA in practise, but the question demands possession plus inherence, which biometrics such as a fingerprint provide.
- ✓
Smart card and fingerprint
Why this is correct
A smart card is a physical token, satisfying the "something you have" factor, while a fingerprint is a biometric trait, satisfying "something you are". Combining these two distinct factor types delivers true multi-factor authentication for remote access, unlike two passwords or two possession factors.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.