Study. uk . com
  1. Home
  2. All questions
  3. Question 313

CISSP study material · question 313 of 500

A device requires a six-digit PIN to unlock a hardware authenticator, and an auditor objects that six digits breaches the password length rules. Why does that objection fail?

  1. Six digits meets the minimum for a password used in a multi-factor process.
  2. The rules apply only to systems assessed at AAL3 and above.
  3. The PIN is an activation secret used locally to unlock the authentication secret, and is never sent to the verifier.
  4. The PIN is exempt because it is numeric rather than alphanumeric.
Show the answer

Answer: C. The PIN is an activation secret used locally to unlock the authentication secret, and is never sent to the verifier.

SP 800-63B distinguishes centrally verified passwords from activation secrets, which are used locally to gain access to the authentication secret and are not sent to the verifier.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 > 3.1.1 Passwords

Challenge yourself on this topic → Study as cards