An organization uses smart cards with PKI certificates for authentication. Users must insert the card and enter a PIN. This is an example of which authentication method?
The smart card holds a PKI certificate (something you have) while the PIN is something you know. Combining these two distinct factors satisfies two-factor authentication, unlike a single-factor method such as certificate-only or password-only verification.
Why this answer
Two-factor authentication requires two different categories of authentication factors. The smart card (something you have) plus the PIN (something you know) combine two distinct factor types, so this is two-factor authentication. The certificate on the card provides cryptographic proof of possession, while the PIN unlocks the card and proves knowledge.
Exam trap
SSCP often tests factor counting — candidates miscount because they treat the certificate and the PIN as two separate 'things' or forget that possession plus knowledge equals exactly two factors, not three.
How to eliminate wrong answers
Option A is wrong because three-factor authentication would require a third, different factor such as a biometric (something you are) in addition to the card and PIN. Option B is wrong because single-factor authentication uses only one factor category; here both possession and knowledge are required. Option D is wrong because biometric authentication relies on a physical characteristic (fingerprint, iris, face), which is not used in this scenario.