nerdexam
(ISC)2

SSCP · Question #34

Which of the following was developed to address some of the weaknesses in Kerberos and uses public key cryptography for the distribution of secret keys and provides additional access control support?

The correct answer is A. SESAME. SESAME (Secure European System for Applications in a Multi-vendor Environment) was specifically designed as an improvement over Kerberos, adding public key cryptography for secret key distribution and introducing Privilege Attribute Certificates (PACs) for enhanced access…

Submitted by yuriko_h· Apr 18, 2026Access Controls

Question

Which of the following was developed to address some of the weaknesses in Kerberos and uses public key cryptography for the distribution of secret keys and provides additional access control support?

Options

  • ASESAME
  • BRADIUS
  • CKryptoKnight
  • DTACACS+

How the community answered

(53 responses)
  • A
    91% (48)
  • B
    6% (3)
  • C
    2% (1)
  • D
    2% (1)

Explanation

SESAME (Secure European System for Applications in a Multi-vendor Environment) was specifically designed as an improvement over Kerberos, adding public key cryptography for secret key distribution and introducing Privilege Attribute Certificates (PACs) for enhanced access control - making it the direct answer here.

Why the distractors are wrong:

  • RADIUS is a network authentication/accounting protocol used for remote access (AAA), unrelated to Kerberos enhancement.
  • KryptoKnight is IBM's authentication protocol - a Kerberos peer, not a successor designed to fix its weaknesses.
  • TACACS+ is Cisco's AAA protocol for device administration, also not related to Kerberos improvement.

Memory tip: Think SESAME opens doors Kerberos couldn't - it "unlocks" the weaknesses of Kerberos by adding public key crypto (the key) and PACs for access control (the door), and the name even sounds like something that grants you extra access ("Open sesame!").

Topics

#Authentication Protocols#Kerberos#Public Key Cryptography#Access Control Systems

Community Discussion

No community discussion yet for this question.

Full SSCP Practice