nerdexam
(ISC)2

SSCP · Question #888

The three classic ways of authenticating yourself to the computer security software are by something you know, by something you have, and by something:

The correct answer is C. you are.. Option C ("you are") completes the classic three-factor authentication model: something you know (passwords, PINs), something you have (smart cards, tokens), and something you are (biometrics like fingerprints, retina scans, or facial recognition). This framework is a foundationa

Submitted by tom_us· Apr 18, 2026Access Controls

Question

The three classic ways of authenticating yourself to the computer security software are by something you know, by something you have, and by something:

Options

  • Ayou need.
  • Bnon-trivial
  • Cyou are.
  • Dyou can get.

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    89% (33)
  • D
    5% (2)

Explanation

Option C ("you are") completes the classic three-factor authentication model: something you know (passwords, PINs), something you have (smart cards, tokens), and something you are (biometrics like fingerprints, retina scans, or facial recognition). This framework is a foundational concept in information security and is widely referenced in certifications like CompTIA Security+.

Why the distractors are wrong:

  • A ("you need") - "need" is not a security category; it describes motivation, not an authentication mechanism.
  • B ("non-trivial") - this is an adjective describing difficulty, not a factor in any authentication model.
  • D ("you can get") - this is too vague and overlaps with "something you have," making it redundant and not a distinct factor.

Memory tip: Think of the three factors as Know → Have → Are - a progression from mental (knowledge), to physical possession (token/card), to biological identity (your body). The acronym KHA or the phrase "I know my card is me" can help lock this in during exams.

Topics

#Authentication factors#Biometrics#Multi-factor authentication (MFA)

Community Discussion

No community discussion yet for this question.

Full SSCP Practice