nerdexam
EC-Council

312-50V10 · Question #266

What is the main reason the use of a stored biometric is vulnerable to an attack?

The correct answer is D. A stored biometric can be stolen and used by an attacker to impersonate the individual identified. A stored biometric is vulnerable primarily because the digital representation can be stolen and replayed by an attacker to impersonate the legitimate user.

Information Security and Ethical Hacking Fundamentals

Question

What is the main reason the use of a stored biometric is vulnerable to an attack?

Options

  • AThe digital representation of the biometric might not be unique, even if the physical characteristic
  • BAuthentication using a stored biometric compares a copy to a copy instead of the original to a
  • CA stored biometric is no longer "something you are" and instead becomes "something you have".
  • DA stored biometric can be stolen and used by an attacker to impersonate the individual identified

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    7% (3)
  • C
    14% (6)
  • D
    77% (34)

Why each option

A stored biometric is vulnerable primarily because the digital representation can be stolen and replayed by an attacker to impersonate the legitimate user.

AThe digital representation of the biometric might not be unique, even if the physical characteristic

Biometric representations are designed to be highly unique; non-uniqueness is not the primary vulnerability of stored biometrics.

BAuthentication using a stored biometric compares a copy to a copy instead of the original to a

While comparing copies introduces some risk, the more critical issue is that a stolen copy gives an attacker persistent, unrevocable impersonation capability.

CA stored biometric is no longer "something you are" and instead becomes "something you have".

Although this is a valid conceptual argument about authentication factors, it describes a theoretical classification concern rather than the direct technical attack vector.

DA stored biometric can be stolen and used by an attacker to impersonate the individual identifiedCorrect

Unlike a physical biometric characteristic such as a fingerprint or iris that remains with the person, a stored digital template can be extracted from a database, intercepted in transit, or captured from a sensor and then replayed or injected into an authentication system. Because the system compares templates rather than performing live verification of a physical trait, a stolen template can be used by anyone to authenticate as the victim indefinitely, since biometrics cannot be revoked and reissued like passwords.

Concept tested: Stored biometric template theft and replay attacks

Source: https://www.nist.gov/publications/biometric-standards-and-guidelines

Topics

#biometrics#stored credentials#identity theft#authentication attack

Community Discussion

No community discussion yet for this question.

Full 312-50V10 Practice