Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 CISSP Exam - Topic 1 Question 114 Discussion

Actual exam question for ISC2's CISSP exam
Question #: 114
Topic #: 1
[All CISSP Questions]

Which of the following is a characteristic of a challenge/response authentication process?

Show Suggested Answer Hide Answer
Suggested Answer: B

A characteristic of a challenge/response authentication process is transmitting a hash based on the user's password. A challenge/response authentication process is a type of authentication method that involves the exchange of a challenge and a response between the authenticator and the authenticatee. The challenge is usually a random or unpredictable value, such as a nonce or a timestamp, that is sent by the authenticator to the authenticatee. The response is usually a value that is derived from the challenge and the user's password, such as a hash or a message authentication code (MAC), that is sent by the authenticatee to the authenticator. The authenticator then verifies the response by applying the same algorithm and password to the challenge, and comparing the results. If the response matches the expected value, the authentication is successful. Transmitting a hash based on the user's password can provide a secure and efficient way of proving the user's identity, without revealing the password in plaintext or requiring the storage of the password on the authenticator. Reference: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 5: Identity and Access Management, page 208; [Official (ISC)2 CISSP CBK Reference, Fifth Edition, Chapter 5: Identity and Access Management, page 297]


Contribute your Thoughts:

0/2000 characters
Merri
4 days ago
I'm not entirely sure, but I think C sounds like something related to CAPTCHA rather than challenge/response.
upvoted 0 times
...
Freeman
9 days ago
I remember practicing with questions about authentication methods, and I feel like A and D are more about password policies than challenge/response.
upvoted 0 times
...
Chanel
14 days ago
I think challenge/response is about verifying something without directly sending the password, so maybe it's B?
upvoted 0 times
...

Save Cancel