- Home
- All questions
- Question 254
CompTIA Security+ study material · question 254 of 611
Which authenticator arrangement satisfies AAL3?
Show the answer
Answer: D. A hardware cryptographic authenticator whose private key cannot be exported
AAL3 requires a phishing-resistant cryptographic authenticator with a non-exportable key. The others meet AAL1 or AAL2.
Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 › Authentication Assurance Levels