nerdexam
GIAC

GCIH · Question #183

Adam works as a Security Analyst for Umbrella Inc. CEO of the company ordered him to implement two-factor authentication for the employees to access their networks. He has told him that he would…

The correct answer is B. Security token. A security token is a physical hardware device that generates or stores authentication credentials and is used alongside a PIN to satisfy two-factor authentication requirements.

Incident Response & Cyber Kill Chain

Question

Adam works as a Security Analyst for Umbrella Inc. CEO of the company ordered him to implement two-factor authentication for the employees to access their networks. He has told him that he would like to use some type of hardware device in tandem with a security or identifying pin number. Adam decides to implement smart cards but they are not cost effective. Which of the following types of hardware devices will Adam use to implement two-factor authentication?

Options

  • ABiometric device
  • BSecurity token
  • CProximity cards
  • DOne Time Password

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    93% (38)
  • D
    5% (2)

Why each option

A security token is a physical hardware device that generates or stores authentication credentials and is used alongside a PIN to satisfy two-factor authentication requirements.

ABiometric device

A biometric device authenticates using a physical characteristic such as a fingerprint or retina scan rather than a PIN-based hardware token combination.

BSecurity tokenCorrect

A security token is a small hardware device - such as an RSA SecurID or FIDO key - that produces a time-based or event-based code which the user combines with a personal PIN to authenticate. This directly satisfies the requirement of 'hardware device in tandem with a security or identifying pin number.' Unlike smart cards, hardware tokens are generally lower-cost and do not require special card-reader infrastructure, addressing the cost-effectiveness concern raised in the scenario.

CProximity cards

Proximity cards use RFID to grant physical access and do not inherently incorporate a PIN-based two-factor authentication mechanism for network access.

DOne Time Password

A one-time password is an authentication method or software mechanism, not a physical hardware device as specified in the requirements.

Concept tested: Hardware-based two-factor authentication with security tokens

Source: https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks

Topics

#two-factor authentication#security token#hardware token#authentication mechanisms

Community Discussion

No community discussion yet for this question.

Full GCIH Practice