CAS-003 · Question #681
A secure facility has a server room that currently is controlled by a simple lock and key. and several administrators have copies of the key. To maintain regulatory compliance, a second lock, which…
The correct answer is C. Fingerprint scanning. Fingerprint scanning satisfies all four criteria. (1) Non-invasive: placing a finger on a smartphone sensor is minimally intrusive compared to iris or vein scanning. (2) Second factor: biometrics fall under 'something you are,' which pairs with 'something you have' (the…
Question
A secure facility has a server room that currently is controlled by a simple lock and key. and several administrators have copies of the key. To maintain regulatory compliance, a second lock, which is controlled by an application on the administrators' smartphones, is purchased and installed. The application has various authentication methods that can be used. The criteria for choosing the most appropriate method are:
- It cannot be invasive to the end user
- It must be utilized as a second factor.
- Information sharing must be avoided
- It must have a low false acceptance rate
Which of the following BEST meets the criteria?
Options
- AFacial recognition
- BSwipe pattern
- CFingerprint scanning
- DComplex passcode
- EToken card
How the community answered
(47 responses)- A2% (1)
- B4% (2)
- C77% (36)
- D11% (5)
- E6% (3)
Explanation
Fingerprint scanning satisfies all four criteria. (1) Non-invasive: placing a finger on a smartphone sensor is minimally intrusive compared to iris or vein scanning. (2) Second factor: biometrics fall under 'something you are,' which pairs with 'something you have' (the smartphone) already in use - making it a true second factor. (3) Information sharing avoided: unlike a PIN (D) or swipe pattern (B), you cannot hand someone your fingerprint, eliminating the risk of credential sharing. (4) Low false acceptance rate (FAR): modern fingerprint sensors have a very low FAR. Facial recognition (A) can have a higher FAR under varied lighting and can be spoofed with photos. Swipe patterns (B) can be observed and shared. Complex passcodes (D) can be shared. Token cards (E) are a physical 'something you have' factor, not a biometric, and can be lost or transferred.
Topics
Community Discussion
No community discussion yet for this question.