nerdexam
(ISC)2

SSCP · Question #174

How can an individual/person best be identified or authenticated to prevent local masquarading attacks?

The correct answer is D. Biometrics. A local masquerading attack involves an adversary pretending to be a legitimate user on the same local system. Credentials like passwords, PINs, and smart cards can all be stolen, shared, or replicated, allowing successful impersonation. Biometrics - fingerprints, iris scans…

Submitted by klara.se· Apr 18, 2026Access Controls

Question

How can an individual/person best be identified or authenticated to prevent local masquarading attacks?

Options

  • AUserId and password
  • BSmart card and PIN code
  • CTwo-factor authentication
  • DBiometrics

How the community answered

(21 responses)
  • A
    14% (3)
  • B
    5% (1)
  • C
    5% (1)
  • D
    76% (16)

Explanation

A local masquerading attack involves an adversary pretending to be a legitimate user on the same local system. Credentials like passwords, PINs, and smart cards can all be stolen, shared, or replicated, allowing successful impersonation. Biometrics - fingerprints, iris scans, voiceprints - are inherently tied to the physical person and cannot be transferred, loaned, or easily replicated. Because biometrics verify who you actually are (rather than what you know or what you have), they are the strongest defense against local masquerading. Two-factor authentication is stronger than a single factor but still relies on possessible or knowable credentials.

Topics

#Authentication factors#Biometric authentication#Masquerading attacks#Access control

Community Discussion

No community discussion yet for this question.

Full SSCP Practice