Study. uk . com
  1. Home
  2. All questions
  3. Question 556

CompTIA Security+ study material · question 556 of 611

Why does NIST apply stricter FIPS 140 requirements to verifiers than to authenticators?

  1. Verifiers hold the users' private keys
  2. A breach at the verifier has a far wider blast radius
  3. Verifiers use longer keys
  4. Authenticators cannot be certified at all
Show the answer

Answer: B. A breach at the verifier has a far wider blast radius

One compromised verifier affects every subscriber, while one compromised authenticator affects one.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 § 2 Authentication Assurance Levels

Challenge yourself on this topic → Study as cards