- Home
- All questions
- Question 312
CompTIA Security+ study material · question 312 of 611
Why must AAL3 authenticators use public-key cryptography to protect the authentication secret?
Show the answer
Answer: C. So that compromising the verifier's stored data does not let an attacker impersonate the user
The verifier holds only a public key, so a breach of the verifier yields nothing that can be replayed as the user.
Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 § 2.3.2