Study. uk . com
  1. Home
  2. All questions
  3. Question 48

CISSP study material · question 48 of 500

A brokerage federates staff logins to an external identity provider. The risk team's worry is a breach of that provider itself: an attacker who controls it could mint assertions naming any employee. Which federation assurance level 3 (FAL3) requirement addresses that specific worry?

  1. The assertion is restricted to a single relying party as its audience and carries replay protection
  2. The relying party redeems an assertion reference over a back channel after authenticating to the identity provider
  3. The relying party validates the assertion and separately observes the subscriber exercise an authenticator tied to that account
  4. The identity provider protects its assertion signing keys in a module validated under the FIPS 140 standard
Show the answer

Answer: C. The relying party validates the assertion and separately observes the subscriber exercise an authenticator tied to that account

FAL3 adds an authenticator the relying party verifies itself, so a forged assertion alone fails. Audience restriction and replay protection are FAL2 baselines that do nothing against a compromised provider.

Source: NIST SP 800-63C Rev. 4 (NIST) — SP 800-63C-4 > 2.4 Federation Assurance Level 3 (FAL3)

Challenge yourself on this topic → Study as cards