Study. uk . com
  1. Home
  2. All questions
  3. Question 333

CISSP study material · question 333 of 500

How do AAL3 reauthentication requirements differ from those at AAL2?

  1. At AAL3 reauthentication is held to the same standard as the initial authentication, with no lighter option inside the overall timeout.
  2. At AAL3 reauthentication is required only after the overall timeout, with no inactivity timeout.
  3. At AAL3 reauthentication may be deferred where the device attests its posture.
  4. At AAL3 reauthentication may use the session secret alone, since the initial authentication was stronger.
Show the answer

Answer: A. At AAL3 reauthentication is held to the same standard as the initial authentication, with no lighter option inside the overall timeout.

SP 800-63B states that unlike AAL2, the AAL3 reauthentication requirements are the same as those for initial authentication at that level.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 > 2.3 Authentication Assurance Level 3

Challenge yourself on this topic → Study as cards