nerdexam
CompTIA

CAS-002 · Question #628

A Chief Information Security Officer (CISO) is approached by a business unit manager who heard a report on the radio this morning about an employee at a competing firm who shipped a VPN token…

The correct answer is B. Implement a biometric factor into the token response process. When a physical token can be transferred to an unauthorized person, adding biometric authentication ensures the token is only usable by the legitimate employee whose biometric is present.

Enterprise Security

Question

A Chief Information Security Officer (CISO) is approached by a business unit manager who heard a report on the radio this morning about an employee at a competing firm who shipped a VPN token overseas so a fake employee could log into the corporate VPN. The CISO asks what can be done to mitigate the risk of such an incident occurring within the organization. Which of the following is the MOST cost effective way to mitigate such a risk?

Options

  • ARequire hardware tokens to be replaced on a yearly basis.
  • BImplement a biometric factor into the token response process.
  • CForce passwords to be changed every 90 days.
  • DUse PKI certificates as part of the VPN authentication process.

How the community answered

(14 responses)
  • B
    79% (11)
  • C
    14% (2)
  • D
    7% (1)

Why each option

When a physical token can be transferred to an unauthorized person, adding biometric authentication ensures the token is only usable by the legitimate employee whose biometric is present.

ARequire hardware tokens to be replaced on a yearly basis.

Replacing tokens yearly does not prevent physical transfer of the token before its replacement date and adds recurring cost without addressing the core vulnerability of token sharing.

BImplement a biometric factor into the token response process.Correct

Biometric authentication ties the login event to the physical characteristics of the legitimate user such as a fingerprint or retina scan, which cannot be shipped or transferred overseas. Even if the hardware token is in someone else's possession, they cannot satisfy the biometric requirement, directly countering the attack vector described. This is the most cost-effective mitigation because it requires no new hardware token infrastructure, only an additional software or firmware layer.

CForce passwords to be changed every 90 days.

Forcing password changes every 90 days does not address the fact that the attacker possesses the physical token and can still authenticate if they also obtain the password.

DUse PKI certificates as part of the VPN authentication process.

PKI certificates authenticate the device or certificate holder but do not inherently prevent a legitimate user from exporting or sharing the certificate with an unauthorized party.

Concept tested: Biometric multi-factor authentication for VPN access

Source: https://pages.nist.gov/800-63-3/sp800-63b.html

Topics

#multi-factor authentication#VPN security#biometrics#hardware tokens

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice