Study. uk . com
  1. Home
  2. All questions
  3. Question 330

CISSP study material · question 330 of 500

A provider plans to deliver a new set of recovery codes through the user's existing web session. What does NIST SP 800-63B require of that session?

  1. It must be authenticated at AAL3, since recovery codes bypass the primary authenticator.
  2. It must be preceded by identity proofing at IAL2.
  3. It must be authenticated at AAL2 or higher and carried over an authenticated protected channel.
  4. It must be established from a device previously bound to the subscriber account.
Show the answer

Answer: C. It must be authenticated at AAL2 or higher and carried over an authenticated protected channel.

Where look-up secrets are delivered over an online session, that session must be authenticated by the subscriber at AAL2 or higher and the secrets delivered over an authenticated protected channel.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 > 3.1.2.1 Look-Up Secret Authenticators

Challenge yourself on this topic → Study as cards