Study. uk . com
  1. Home
  2. All questions
  3. Question 278

CompTIA Security+ study material · question 278 of 611

What does the AAL2 requirement for replay resistance prevent?

  1. A user reusing the same password on another site
  2. An attacker guessing the password offline
  3. A session identifier being predicted
  4. A captured authentication message being reused for a later login
Show the answer

Answer: D. A captured authentication message being reused for a later login

Replay resistance means the observed exchange cannot be replayed, which defeats passive capture on the network.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 § 2.2.2

Challenge yourself on this topic → Study as cards