050-80-CASECURID01 · Question #40
The RSA Authentication Manager Report options can assist you in
The correct answer is D. Authentication Manager will request the user for next tokencode, adjust the user's token. A user has an RSA SecurID Key Fob. The Key Fob Change Interval is 60 seconds and has been used successfully in the past. If the RSA Authentication Manager is now out of synch with the token by 2 minutes, what will happen when the user tries to authenticate? Denied" message…
Question
The RSA Authentication Manager Report options can assist you in
Options
- AAuthentication Manager will automatically adjust the token offset value and authenticate
- BAuthentication Manager will reject the PASSCODE and the user will receive an "Access
- CAuthentication Manager will post a "Token Requires Resync" message in the log and
- DAuthentication Manager will request the user for next tokencode, adjust the user's token
How the community answered
(36 responses)- A17% (6)
- B3% (1)
- C8% (3)
- D72% (26)
Explanation
A user has an RSA SecurID Key Fob. The Key Fob Change Interval is 60 seconds and has been used successfully in the past. If the RSA Authentication Manager is now out of synch with the token by 2 minutes, what will happen when the user tries to authenticate? Denied" message. deny access to the user. offset value, and authenticate the user.
Topics
Community Discussion
6D is the right call here. When Authentication Manager detects a token that is out of sync, it challenges the user for the next tokencode, uses that second value to calculate and correct the offset, and then grants access, so the resync happens inline without admin intervention and without locking the user out.
Does AM politely beg for your next tokencode when things drift?
Yeah, "politely beg" is pretty accurate, the AM enforces Next Tokencode mode and won't let you proceed until you enter it, which is less a request and more a hard gate.
Option B is tempting if you confuse reject with resync, but D is the documented behavior per the RSA Authentication Manager Administration Guide.
The options are cut off which makes this frustrating, but D is the only one that describes the actual resync flow, where Auth Manager challenges for the next tokencode to confirm clock drift and then adjusts the offset. A is also partially true in concept but D captures the interactive resync steps correctly, so D is the answer.
Carlos nailed it, and here is the sticky image that locks D in forever: picture the Auth Manager as a skeptical bouncer who does not just believe your clock is off, he makes you flash the NEXT tokencode so he can measure the drift himself and scribble the offset correction in his little notebook, which is exactly the interactive challenge-response resync that only D describes.