ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Easy

A financial institution is implementing a new customer-facing portal that requires strong authentication for online banking transactions. The security team wants to incorporate a method where users are prompted for a one-time passcode generated by a mobile application on their registered smartphone. Which authentication factor does this scenario primarily represent?

  1. ASomething You Are
  2. BSomething You Have
  3. CSomething You Know
  4. DSomething You Do
Show answer & explanation

Correct answer: B. Something You Have

A one-time passcode generated by a mobile application on a registered smartphone represents 'Something You Have,' as the user possesses the physical device (smartphone) that generates the code.

Why the other options are wrong

  • A. 'Something You Are' refers to biometric characteristics (e.g., fingerprint, facial scan).
  • C. 'Something You Know' refers to secrets like passwords or PINs.
  • D. 'Something You Do' refers to actions like a specific gesture, signature, or typing cadence.

Authentication Factors

Categories of evidence used to verify a user's identity during authentication.

  • Something You Know (password, PIN)
  • Something You Have (token, smart card, phone)
  • Something You Are (biometrics)
  • Something You Do (behavioral biometrics, gestures)

Memory trick: KISS: Know, In-possession, Self, Skill.

More Identity and Access Management (IAM) questions