SSCP Systems Security Certified PractitionerAccess ControlsMedium
A company is implementing a new system that requires users to authenticate using a cryptographic key stored on a smart card, coupled with a PIN. This combination of authentication factors falls under which category of authentication?
- AType 1: Something you know
- BType 2: Something you have
- CType 3: Something you are
- DMulti-factor authentication
Show answer & explanationAnswer & explanation
Correct answer: D. Multi-factor authentication
The scenario describes using a PIN (something you know) and a smart card with a cryptographic key (something you have). Since two distinct types of authentication factors are required, this is an example of multi-factor authentication.
Why the other options are wrong
- A. A PIN is 'something you know', but the scenario also includes a smart card.
- B. A smart card is 'something you have', but the scenario also includes a PIN.
- C. 'Something you are' refers to biometrics (fingerprint, iris scan), which are not mentioned.
Multi-Factor Authentication (MFA)
An authentication method that requires a user to provide two or more verification factors from independent categories to gain access to a resource.
- Significantly enhances security over single-factor authentication.
- Commonly uses a combination of 'something you know', 'something you have', and 'something you are'.
- Reduces the risk of unauthorized access even if one factor is compromised.
Memory trick: KHA: Know, Have, Are – for solid authentication.