nerdexam
CompTIA

CAS-003 · Question #669

A company is implementing a new secure identity application, given the following requirements - The cryptographic secrets used in the application must never be exposed to users or the OS - The…

The correct answer is B. Biometrics E. NFC. NFC (Near Field Communication) (E) is required for compatibility with proximity-based badge reader systems, enabling contactless communication between the mobile device and the badge reader. Biometrics (B) is required because modern mobile biometric systems (e.g., Apple's…

Technical Integration of Enterprise Security

Question

A company is implementing a new secure identity application, given the following requirements

  • The cryptographic secrets used in the application must never be exposed to users or the OS
  • The application must work on mobile devices.
  • The application must work with the company's badge reader system

Which of the following mobile device specifications are required for this design? (Select TWO).

Options

  • ASecure element
  • BBiometrics
  • CUEFI
  • DSEAndroid
  • ENFC
  • FHSM

How the community answered

(50 responses)
  • A
    2% (1)
  • B
    84% (42)
  • C
    8% (4)
  • D
    4% (2)
  • F
    2% (1)

Explanation

NFC (Near Field Communication) (E) is required for compatibility with proximity-based badge reader systems, enabling contactless communication between the mobile device and the badge reader. Biometrics (B) is required because modern mobile biometric systems (e.g., Apple's Secure Enclave or Android's Trusted Execution Environment) bind cryptographic keys to biometric authentication in a way that those keys never leave the secure hardware and are never exposed to the OS or user - satisfying the first requirement. While a Secure Element (A) similarly protects keys, the combination of Biometrics for OS-isolated key binding and NFC for badge reader interoperability best fits all three stated requirements for a mobile-first secure identity application.

Topics

#mobile security#NFC#biometrics#badge reader integration

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice