SSCP Systems Security Certified PractitionerAccess ControlsMedium

A company is implementing a new system that requires users to authenticate using a cryptographic key stored on a smart card, coupled with a PIN. This combination of authentication factors falls under which category of authentication?

  1. AType 1: Something you know
  2. BType 2: Something you have
  3. CType 3: Something you are
  4. DMulti-factor authentication
Show answer & explanation

Correct answer: D. Multi-factor authentication

The scenario describes using a PIN (something you know) and a smart card with a cryptographic key (something you have). Since two distinct types of authentication factors are required, this is an example of multi-factor authentication.

Why the other options are wrong

  • A. A PIN is 'something you know', but the scenario also includes a smart card.
  • B. A smart card is 'something you have', but the scenario also includes a PIN.
  • C. 'Something you are' refers to biometrics (fingerprint, iris scan), which are not mentioned.

Multi-Factor Authentication (MFA)

An authentication method that requires a user to provide two or more verification factors from independent categories to gain access to a resource.

  • Significantly enhances security over single-factor authentication.
  • Commonly uses a combination of 'something you know', 'something you have', and 'something you are'.
  • Reduces the risk of unauthorized access even if one factor is compromised.

Memory trick: KHA: Know, Have, Are – for solid authentication.

More Access Controls questions