Cognitive password

A knowledge-based credential drawn from personal facts or opinions, such as a first pet's name, used for login or account recovery; weak because many answers can be found or guessed.

A cognitive password is a question-and-answer credential based on facts or preferences the user can recall without memorising anything new: a mother’s maiden name, a first school, a favourite film. Such questions have commonly been used for self-service password reset and account recovery, and sometimes as an extra login step. The approach is a form of knowledge-based authentication, and it is “something you know” as an authentication factor.

Current NIST guidance takes a clear line against it. NIST SP 800-63-4 states that knowledge-based authentication does not constitute an acceptable secret for digital authentication, and SP 800-63B-4 says verifiers must not prompt subscribers to use knowledge-based questions or security questions when choosing passwords. The weakness is that many answers are public, discoverable on social media, guessable from a short list, or known to family and colleagues. Adding a cognitive question to a password also does not produce multi-factor authentication, because both are the same factor type. Older study material still describes them as a recovery method.

Exam relevance: a scenario is likely to present security questions as a login or recovery control and ask about their strength. Candidates are expected to see them as weak knowledge-based evidence, to reject a password plus a security question as multi-factor, and to prefer stronger recovery routes such as a bound second authenticator.