- Home
- All questions
- Question 48
CISSP study material · question 48 of 500
A brokerage federates staff logins to an external identity provider. The risk team's worry is a breach of that provider itself: an attacker who controls it could mint assertions naming any employee. Which federation assurance level 3 (FAL3) requirement addresses that specific worry?
Show the answer
Answer: C. The relying party validates the assertion and separately observes the subscriber exercise an authenticator tied to that account
FAL3 adds an authenticator the relying party verifies itself, so a forged assertion alone fails. Audience restriction and replay protection are FAL2 baselines that do nothing against a compromised provider.
Source: NIST SP 800-63C Rev. 4 (NIST) — SP 800-63C-4 > 2.4 Federation Assurance Level 3 (FAL3)