ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a security review you must confirm that the new online banking portal implements true multi-factor authentication (MFA). Which of the following credential pairings satisfies current MFA requirements by using two different factor categories?
A strong password entered by the user and a U2F hardware security key that must be tapped during login.
Face recognition followed by a voiceprint verification on the same device.
A username and complex password followed by answering two personal security questions.
A one-time password from a phone-based authenticator app and an SMS code sent to that same phone.
Multi-factor authentication demands two or more independent factors from different categories: something you know (knowledge), something you have (possession), or something you are (inherence). A strong password is a knowledge factor, while a U2F hardware security key is a possession factor, so their combination meets the MFA definition.
The remaining options fail because they rely on factors from the same category:
Security questions and a password are both knowledge factors.
Face recognition and a voiceprint are both inherence (biometric) factors.
SMS and app-based OTP codes delivered to the same phone both rely on possession of that phone, so they do not add a second factor.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why are knowledge, possession, and inherence considered distinct MFA categories?
Open an interactive chat with Bash
How does a U2F hardware security key work for authentication?
Open an interactive chat with Bash
Why isn’t using only smartphone-based OTP codes considered multi-factor authentication?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .