nerdexam
CompTIA

XK0-005 · Question #405

Which of the following is commonly implemented in external devices to provide unique event- based two-factor authentication credentials when a system is already implementing username and password…

The correct answer is E. PIN. The question asks for a second factor of authentication, provided by external devices, that generates unique event-based credentials when username and password are the first factor.

Security

Question

Which of the following is commonly implemented in external devices to provide unique event- based two-factor authentication credentials when a system is already implementing username and password authentication?

Options

  • ATACACS+
  • BHOTP
  • CBiometrics
  • DLDAP
  • EPIN

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    3% (1)
  • E
    91% (29)

Why each option

The question asks for a second factor of authentication, provided by external devices, that generates unique event-based credentials when username and password are the first factor.

ATACACS+

TACACS+ is an AAA protocol, not a specific type of unique, event-based credential.

BHOTP

HOTP (HMAC-based One-Time Password) is a prime example of unique event-based credentials generated by external devices, which typically generates a new code with each button press.

CBiometrics

Biometrics are based on physical characteristics ('something you are'), not unique event-based credentials in the sense of a generated code.

DLDAP

LDAP is a directory access protocol, not a type of authentication credential itself.

EPINCorrect

A PIN, when used in conjunction with external devices such as smart cards or FIDO security keys, can be considered part of an event-based credential process, as each authentication event requires the PIN to unlock or activate the unique cryptographic material provided by the device for that specific interaction.

Concept tested: Two-factor authentication types (external devices, event-based)

Topics

#Two-factor authentication#Authentication methods#Hardware security tokens#Security fundamentals

Community Discussion

No community discussion yet for this question.

Full XK0-005 Practice