- Home
- All questions
- Question 331
CISSP study material · question 331 of 500
A consumer service authenticating at AAL1 asks how long a session may run before reauthentication, and whether an inactivity timeout is compulsory. What does NIST SP 800-63B say?
Show the answer
Answer: D. The overall timeout should be no more than 30 days, and an inactivity timeout may be applied but is not required.
At AAL1 a definite reauthentication timeout should be no more than 30 days, and an inactivity timeout may be applied but is not required at that level.
Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 > 2.1 Authentication Assurance Level 1