Courseiva
Access Controls →mediumMultiple Choice

Multi-Factor Authentication: Examples of Different Factors

An organization wants to implement multi-factor authentication (MFA) for remote access. Which combination represents something you have and something you are?

⚠ Common exam trap

SSCP often tests factor-category confusion — candidates see two credentials and assume MFA, missing that both must come from different categories (know, have, are).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Smart card and fingerprint

A smart card is a physical token the user possesses (something you have), and a fingerprint is a biometric trait inherent to the user (something you are). Combining them satisfies the requirement for two different MFA factor categories. This is a classic possession-plus-inherence pairing used in high-assurance environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Password and security question

    Why it's wrong here

    Both a password and a security question are knowledge factors, so this is single-factor authentication repeated, not MFA. It tempts because security questions appear as a second prompt, but they test recall rather than possession or inherence, so they add no distinct factor category.

  • ✗

    Smart card and PIN

    Why it's wrong here

    A smart card is something you have, but a PIN is something you know, so this pairs possession with knowledge rather than inherence. It is tempting because smart card plus PIN is a classic strong two-factor scheme, yet the question requires something you are, satisfied only by a biometric such as a fingerprint.

  • ✗

    Password and one-time passcode (OTP)

    Why it's wrong here

    A password is something you know and an OTP is also something you know or possess temporarily, so both factors sit in knowledge or possession, not inherence. This pairing is common because it delivers MFA in practise, but the question demands possession plus inherence, which biometrics such as a fingerprint provide.

  • ✓

    Smart card and fingerprint

    Why this is correct

    A smart card is a physical token, satisfying the "something you have" factor, while a fingerprint is a biometric trait, satisfying "something you are". Combining these two distinct factor types delivers true multi-factor authentication for remote access, unlike two passwords or two possession factors.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.