ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Hard

A security architect is designing an authentication system for a critical infrastructure facility. The system must provide strong assurance of identity and resist attacks like replay attacks and credential compromise. Which authentication mechanism, when properly implemented, offers the highest level of assurance against these threats by using cryptographic techniques?

  1. ABiometric authentication with liveness detection
  2. BCertificate-based authentication with smart cards
  3. CMulti-factor authentication (MFA) using SMS OTPs
  4. DPassword-based authentication with strong password policies
Show answer & explanation

Correct answer: B. Certificate-based authentication with smart cards

Certificate-based authentication, especially with smart cards, uses public key cryptography to establish identity. The private key, stored securely on the smart card, never leaves the device, making it highly resistant to replay attacks and credential compromise, offering a very strong root of trust.

Why the other options are wrong

  • A. Biometric authentication can be robust, but still faces challenges like presentation attacks (spoofing) and the inability to revoke a compromised biometric, and it doesn't inherently prevent replay attacks of the authentication token without additional cryptography.
  • C. MFA with SMS OTPs is better than passwords alone, but SMS can be intercepted (SIM swapping) and OTPs can sometimes be phished, reducing its overall assurance compared to cryptographic methods.
  • D. Password-based authentication, even with strong policies, is susceptible to various attacks like phishing, keyloggers, and brute-force attempts, offering lower assurance.

Certificate-Based Authentication

A method of authenticating users or devices using digital certificates, which rely on public key cryptography to verify identity.

  • Uses public/private key pairs.
  • Private key is typically hardware-protected (e.g., smart card).
  • Resistant to replay attacks and robust against phishing.

Memory trick: Keys, Biometrics, Certificates: The Strongest Security Gates

More Identity and Access Management (IAM) questions