CISSP-ISSAP · Question #184
Which of the following protocols is used to compare two values calculated using the Message Digest (MD5) hashing function?
The correct answer is A. CHAP. CHAP (Challenge Handshake Authentication Protocol) is correct because it works by having both the authenticator and the client independently compute an MD5 hash of a shared secret combined with a challenge value, then compares the two results - if they match, authentication…
Question
Which of the following protocols is used to compare two values calculated using the Message Digest (MD5) hashing function?
Options
- ACHAP
- BPEAP
- CEAP
- DEAP-TLS
How the community answered
(54 responses)- A72% (39)
- B4% (2)
- C7% (4)
- D17% (9)
Explanation
CHAP (Challenge Handshake Authentication Protocol) is correct because it works by having both the authenticator and the client independently compute an MD5 hash of a shared secret combined with a challenge value, then compares the two results - if they match, authentication succeeds. This "compare two MD5 values" mechanism is the defining characteristic of CHAP.
Why the distractors are wrong:
- PEAP wraps EAP inside a TLS tunnel for protection but doesn't define an MD5 comparison mechanism itself.
- EAP is a framework that supports many authentication methods; it doesn't specify MD5 on its own.
- EAP-TLS uses mutual certificate-based authentication, relying on PKI and TLS handshakes - not MD5 hashing.
Memory tip: Think "CHAP Checks Checksum" - the Challenge-Handshake part is exactly the MD5 hash comparison happening on both ends to verify identity without ever sending the password in plaintext.
Topics
Community Discussion
No community discussion yet for this question.