Study. uk . com
  1. Home
  2. All questions
  3. Question 331

CISSP study material · question 331 of 500

A consumer service authenticating at AAL1 asks how long a session may run before reauthentication, and whether an inactivity timeout is compulsory. What does NIST SP 800-63B say?

  1. There is no timeout at AAL1; reauthentication is required only on privilege change.
  2. The overall timeout must be no more than 24 hours, with a one-hour inactivity timeout.
  3. The overall timeout must be no more than 12 hours, with a 15-minute inactivity timeout.
  4. The overall timeout should be no more than 30 days, and an inactivity timeout may be applied but is not required.
Show the answer

Answer: D. The overall timeout should be no more than 30 days, and an inactivity timeout may be applied but is not required.

At AAL1 a definite reauthentication timeout should be no more than 30 days, and an inactivity timeout may be applied but is not required at that level.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 > 2.1 Authentication Assurance Level 1

Challenge yourself on this topic → Study as cards