Courseiva
Access Controls →easyMultiple Choice

SSCP Access Controls Practice Question

Which of the following is a common method for implementing multi-factor authentication (MFA) using something you have and something you know?

⚠ Common exam trap

SSCP often tests whether candidates recognize that two methods from the same factor category (e.g., two biometrics or two passwords) do not constitute MFA — the trap is picking an option that sounds like two factors but is actually one category.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Smart card and PIN

A smart card (something you have) combined with a PIN (something you know) satisfies the two-factor requirement using two distinct authentication factor categories. This is the classic possession-plus-knowledge MFA pairing and is widely deployed in PIV/CAC and physical access systems. The other options either use two factors from the same category or only one factor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Fingerprint and retina scan

    Why it's wrong here

    Fingerprint and retina scans are both inherence factors, so this pairs two biometrics rather than combining possession with knowledge. It is tempting because biometrics are common in MFA deployments, but they would be the right choice when the requirement is something you are, not something you have plus something you know.

  • ✓

    Smart card and PIN

    Why this is correct

    A smart card satisfies the "something you have" factor, while the PIN supplies "something you know". Combining a physical token with a memorised secret meets the stem's two-factor requirement, unlike single-factor or same-category pairings. This hardware-plus-knowledge pairing is a standard MFA implementation.

  • ✗

    Password and security question

    Why it's wrong here

    A password and a security question are both knowledge factors, so no possession factor is present and the MFA requirement is unmet. It is tempting because two separate prompts appear to add security, and it would be correct as knowledge-based account recovery rather than multi-factor authentication.

  • ✗

    Username and password

    Why it's wrong here

    A username and password are both knowledge factors, so this supplies only something you know and never satisfies the something-you-have requirement. It is tempting because it is the familiar login pattern, and it would be correct for single-factor authentication rather than MFA.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.