- Home
- All questions
- Question 255
CompTIA Security+ study material · question 255 of 611
An application is being assessed at AAL2. What must its verifier offer users?
Show the answer
Answer: C. At least one phishing-resistant authentication option
AAL2 requires a phishing-resistant option to be available, and federal agencies must actually require its use.
Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 › AAL2 › Authenticator and Verifier Requirements