Hardware token
A physical device that proves possession during authentication, either by displaying a one-time code or by performing a cryptographic operation with a key stored inside it.
A hardware token is a dedicated physical device used as the something-you-have authentication factor. There are two broad kinds. One-time password tokens hold a secret seed and display a short code, generated from a counter as in HOTP or from the time as in TOTP, which the user types in. Cryptographic tokens, such as USB or NFC security keys and smart cards, hold a private key and prove possession by signing a challenge from the verifier. Unlike a software token on a phone, it keeps its secret in a device built for that purpose.
The two kinds differ on phishing. NIST SP 800-63B-4 states that OTP authentication is not phishing-resistant, because a user can be led to type a valid code into a fake site that relays it. A cryptographic token that binds its response to the real site’s name, as FIDO2 security keys do, can be phishing-resistant. Either kind can be lost or stolen, so tokens are commonly combined with a PIN or password for multi-factor authentication, and lost devices need to be revoked.
Exam relevance: a scenario is likely to offer several second factors and ask which best resists phishing, where a cryptographic security key is expected to rank above a code-displaying token. Candidates are also expected to classify any token as something you have, whatever its form.