Study. uk . com
  1. Home
  2. All questions
  3. Question 255

CompTIA Security+ study material · question 255 of 611

An application is being assessed at AAL2. What must its verifier offer users?

  1. Mandatory biometric enrolment
  2. A hardware token issued by the organisation
  3. At least one phishing-resistant authentication option
  4. A password of at least twenty characters
Show the answer

Answer: C. At least one phishing-resistant authentication option

AAL2 requires a phishing-resistant option to be available, and federal agencies must actually require its use.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 › AAL2 › Authenticator and Verifier Requirements

Challenge yourself on this topic → Study as cards