Study. uk . com
  1. Home
  2. All questions
  3. Question 270

CompTIA Security+ study material · question 270 of 611

An organisation wants to use cloud-synced passkeys to meet AAL3. Why will this fail?

  1. Passkeys are not phishing-resistant
  2. Passkeys cannot demonstrate authentication intent
  3. Syncable authenticators require an exportable private key, which AAL3 forbids
  4. AAL3 requires a password in addition to the passkey
Show the answer

Answer: C. Syncable authenticators require an exportable private key, which AAL3 forbids

AAL3 requires the private key to stay in hardware, which is incompatible with syncing the credential between devices.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 § 2.3 and Appendix B

Challenge yourself on this topic → Study as cards