Authentication factor

A category of evidence used to authenticate: something you know, something you have or something you are. MFA requires more than one distinct type, not more than one item.

An authentication factor is a type of evidence a claimant offers to prove an identity. NIST SP 800-63B-4 names three types: something you know (such as a password or PIN), something you have (such as a hardware token, smart card or registered phone) and something you are (a biometric characteristic). The authenticator is the thing that supplies the factor; a single authenticator can carry more than one, as a cryptographic device unlocked by a fingerprint does.

Multi-factor authentication requires more than one distinct type of factor. Two passwords, or a password plus a security question, are the same type twice and remain single-factor. Location and time of day are sometimes listed as extra factors (“somewhere you are”), but they are more precisely treated as context that a risk-based access control decision can weigh, not as factors of the same kind. Behavioural traits such as typing rhythm are different: SP 800-63B-4 counts them as biometrics, so they belong to something you are. A biometric, unlike a password, is not a secret.

Exam relevance: a scenario is likely to list the credentials a user presents and ask whether the result is multi-factor. Candidates are expected to count factor types, not items, and to treat location and time as context unless the question frames them otherwise.