Study. uk . com
  1. Home
  2. All questions
  3. Question 256

CompTIA Security+ study material · question 256 of 611

A vendor claims their fingerprint-only login is multi-factor authentication. What is wrong with that claim?

  1. Biometrics may only be used at AAL1
  2. Fingerprints are a knowledge factor, not an inherence factor
  3. Fingerprint readers cannot meet FIPS 140
  4. A biometric is not an authenticator by itself and must accompany a physical authenticator
Show the answer

Answer: D. A biometric is not an authenticator by itself and must accompany a physical authenticator

The physical authenticator supplies 'something you have' while the biometric match supplies 'something you are'.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 › AAL2 › Permitted Authenticator Types

Challenge yourself on this topic → Study as cards