312-50V11 · Question #173
By using a smart card and pin, you are using a two-factor authentication that satisfies
The correct answer is B. Something you have and something you know. A smart card is a physical token (something you have) and a PIN is a memorized secret (something you know), satisfying the two most common multi-factor authentication categories.
Question
By using a smart card and pin, you are using a two-factor authentication that satisfies
Options
- ASomething you know and something you are
- BSomething you have and something you know
- CSomething you have and something you are
- DSomething you are and something you remember
How the community answered
(27 responses)- B93% (25)
- C4% (1)
- D4% (1)
Why each option
A smart card is a physical token (something you have) and a PIN is a memorized secret (something you know), satisfying the two most common multi-factor authentication categories.
A PIN is classified as 'something you know,' not 'something you are'; the 'something you are' category refers exclusively to biometric factors such as fingerprints or retinal scans.
A smart card is a physical token the user possesses, placing it in the 'something you have' category. A PIN is a memorized numeric secret known only to the user, placing it in the 'something you know' category. Together they form a valid two-factor combination covering both categories.
'Something you are' refers to biometric authentication, not a PIN, so this pairing does not correctly describe a smart card plus PIN combination.
'Something you are' is a biometric factor unrelated to a PIN, and 'something you remember' is not a recognized standard authentication factor category.
Concept tested: Multi-factor authentication factor categories
Source: https://pages.nist.gov/800-63-3/sp800-63b.html
Topics
Community Discussion
No community discussion yet for this question.