nerdexam
(ISC)2

CISSP-ISSAP · Question #175

Which of the following authentication methods prevents unauthorized execution of code on remote systems?

The correct answer is B. S-RPC. S-RPC (Secure Remote Procedure Call) directly addresses remote code execution by adding authentication to the RPC mechanism - the very system by which code is invoked on remote machines - ensuring only authorized callers can trigger remote procedures. TACACS and RADIUS are both…

Identity and Access Management (IAM) Architecture

Question

Which of the following authentication methods prevents unauthorized execution of code on remote systems?

Options

  • ATACACS
  • BS-RPC
  • CRADIUS
  • DCHAP

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    83% (19)
  • C
    9% (2)
  • D
    4% (1)

Explanation

S-RPC (Secure Remote Procedure Call) directly addresses remote code execution by adding authentication to the RPC mechanism - the very system by which code is invoked on remote machines - ensuring only authorized callers can trigger remote procedures. TACACS and RADIUS are both AAA (Authentication, Authorization, Accounting) frameworks, but they control network access (device login, VPN, dial-in), not whether a remote procedure or code block can be executed. CHAP is a challenge-response protocol used to verify identity over PPP links, again focused on connection authentication rather than governing code execution on a remote host.

Memory tip: RPC = Remote Procedure Call - it's literally the mechanism for running code on another machine. The "S" in S-RPC just means it's the secured version. If the question involves executing code remotely, lock onto the word "Procedure" as your clue.

Topics

#Secure RPC#Authentication#Remote code execution#RPC security

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSAP Practice