Courseiva
hardMultiple Select

SSCP Practice Question: Which THREE of the following are common methods…

Which THREE of the following are common methods for implementing multifactor authentication (MFA)?

⚠ Common exam trap

ISC2 often tests the distinction between using multiple instances of the same factor (e.g., two biometrics or two passwords) versus using factors from different categories, which is the core requirement for true MFA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Password and SMS code

Option B (Password and SMS code) is correct because it combines something you know (a password) with something you have (a one-time code delivered to your registered phone), which are two distinct authentication factors. Option C (Smart card and PIN) is correct because it pairs something you have (the smart card) with something you know (the PIN), satisfying MFA's requirement for different factor types. Option E (Fingerprint and smart card) is correct because it combines something you are (a biometric fingerprint) with something you have (the smart card), again using two separate factor categories. Option A is not correct because a retina scan and facial recognition are both inherence (biometric) factors, so they represent the same factor type rather than multifactor authentication. Option D is not correct because a password and a security question are both knowledge-based factors, so they do not constitute true MFA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Retina scan and facial recognition

    Why it's wrong here

    A retina scan and facial recognition are both biometrics, so combining them stays within a single authentication factor rather than spanning categories. It is tempting because biometrics feel advanced, yet MFA requires different factor types, such as something you know plus something you have.

  • ✓

    Password and SMS code

    Why this is correct

    Combining a password (knowledge factor) with an SMS code (possession factor) satisfies the stem's requirement for a common MFA method, since it draws on two distinct authentication categories. SMS delivery to a registered mobile number is widely deployed, though vulnerable to SIM-swapping and interception, which is why Microsoft Entra ID now favours stronger possession factors.

  • ✓

    Smart card and PIN

    Why this is correct

    Smart card plus PIN combines a physical possession factor with a knowledge factor, satisfying MFA's requirement for two distinct authentication categories. The PIN unlocks the certificate stored on the card, so both elements are validated together. This matches the stem's request for a common MFA implementation method.

  • ✗

    Password and security question

    Why it's wrong here

    A password and a security question are both knowledge-based, so they remain one factor despite appearing as two prompts. It is tempting because two challenges look like two factors, but MFA demands distinct categories, for example a password combined with a token or biometric.

  • ✓

    Fingerprint and smart card

    Why this is correct

    Fingerprint and smart card satisfy MFA by combining inherence (a biometric fingerprint) with possession (a physical smart card token). These represent two distinct authentication factors, directly meeting the stem's requirement for multifactor implementation methods, unlike single-factor approaches that rely on one category alone.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.