Study. uk . com
  1. Home
  2. All questions
  3. Question 275

CompTIA Security+ study material · question 275 of 611

A service uses strong multi-factor authentication but never learns the user's real name. Is this consistent with NIST guidance?

  1. No, strong authentication requires identity proofing
  2. Yes, because proofing and authentication are separate decisions and pseudonymous accounts are supported
  3. Yes, but only at AAL1
  4. No, because the account cannot be recovered
Show the answer

Answer: B. Yes, because proofing and authentication are separate decisions and pseudonymous accounts are supported

Authentication asks whether the same person is returning; proofing asks who they are. The two levels are chosen independently.

Source: NIST SP 800-63A Rev. 4 (NIST) — SP 800-63A-4 › Identity Assurance Levels

Challenge yourself on this topic → Study as cards