Study. uk . com
  1. Home
  2. All questions
  3. Question 312

CompTIA Security+ study material · question 312 of 611

Why must AAL3 authenticators use public-key cryptography to protect the authentication secret?

  1. To satisfy the fifteen-character password minimum
  2. To permit the authenticator to be shared between users
  3. So that compromising the verifier's stored data does not let an attacker impersonate the user
  4. To allow the key to be backed up safely
Show the answer

Answer: C. So that compromising the verifier's stored data does not let an attacker impersonate the user

The verifier holds only a public key, so a breach of the verifier yields nothing that can be replayed as the user.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 § 2.3.2

Challenge yourself on this topic → Study as cards