Study. uk . com
  1. Home
  2. All questions
  3. Question 47

CISSP study material · question 47 of 500

An agency runs a case-management system at Authentication Assurance Level 3 (AAL3). Analysts complain about being signed out during long reviews and ask to inherit the timings used by the intranet, which runs at Authentication Assurance Level 2 (AAL2). Under NIST SP 800-63B-4, which session limits must the case-management system keep?

  1. A 12-hour ceiling on the session, with reauthentication forced after one hour of inactivity.
  2. A 24-hour ceiling on the session, with reauthentication forced after one hour of inactivity.
  3. A 30-day ceiling on the session, with reauthentication forced only when the subscriber changes device.
  4. A 12-hour ceiling on the session, with reauthentication forced after 15 minutes of inactivity.
Show the answer

Answer: D. A 12-hour ceiling on the session, with reauthentication forced after 15 minutes of inactivity.

AAL3 caps sessions at 12 hours and reauthenticates after 15 minutes idle; the 24-hour and one-hour pairing the analysts want belongs to AAL2.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 > Reauthentication (AAL1, AAL2, AAL3)

Challenge yourself on this topic → Study as cards