nerdexam
(ISC)2

CISSP-ISSAP · Question #188

Mark has been hired by a company to work as a Network Assistant. He is assigned the task to configure a dial-up connection. He is configuring a laptop. Which of the following protocols should he…

The correct answer is C. PAP. PAP (Password Authentication Protocol) must be disabled because it transmits passwords in cleartext - meaning anyone intercepting the dial-up connection can read the credentials directly. The other three options all use encryption or challenge-response mechanisms, so disabling…

Identity and Access Management (IAM) Architecture

Question

Mark has been hired by a company to work as a Network Assistant. He is assigned the task to configure a dial-up connection. He is configuring a laptop. Which of the following protocols should he disable to ensure that the password is encrypted during remote access?

Options

  • ASPAP
  • BMSCHAP
  • CPAP
  • DMSCHAP V2

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    5% (2)
  • C
    76% (28)
  • D
    14% (5)

Explanation

PAP (Password Authentication Protocol) must be disabled because it transmits passwords in cleartext - meaning anyone intercepting the dial-up connection can read the credentials directly. The other three options all use encryption or challenge-response mechanisms, so disabling them would reduce security rather than improve it.

  • SPAP (Shiva PAP) is wrong because it does encrypt passwords, making it acceptable for secure remote access.
  • MSCHAP is wrong because it uses a challenge-response mechanism that never sends the actual password over the wire.
  • MSCHAP V2 is wrong because it is an improved encrypted protocol - disabling it would be counterproductive.

Memory tip: Think "PAP = Plain As Paper." If you see PAP in a question about encryption or security, it's almost always the weak link to disable or avoid, since it offers zero password protection.

Topics

#PAP protocol#Dial-up authentication#Password encryption#MSCHAP

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSAP Practice