Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam SSCP All Questions

View all questions & answers for the SSCP exam

Exam SSCP topic 1 question 81 discussion

Actual exam question from ISC's SSCP
Question #: 81
Topic #: 1
[All SSCP Questions]

Which of the following would be true about Static password tokens?

  • A. The owner identity is authenticated by the token
  • B. The owner will never be authenticated by the token.
  • C. The owner will authenticate himself to the system.
  • D. The token does not authenticates the token owner but the system.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
Password Tokens -
Tokens are electronic devices or cards that supply a user's password for them. A token system can be used to supply either a static or a dynamic password.
There is a big difference between the static and dynamic systems, a static system will normally log a user in but a dynamic system the user will often have to log themselves in.
Static Password Tokens:
The owner identity is authenticated by the token. This is done by the person who issues the token to the owner (normally the employer). The owner of the token is now authenticated by "something you have". The token authenticates the identity of the owner to the information system. An example of this occurring is when an employee swipes his or her smart card over an electronic lock to gain access to a store room.
Synchronous Dynamic Password Tokens:
This system is a lot more complex then the static token password. The synchronous dynamic password tokens generate new passwords at certain time intervals that are synched with the main system. The password is generated on a small device similar to a pager or a calculator that can often be attached to the user's key ring. Each password is only valid for a certain time period, typing in the wrong password in the wrong time period will invalidate the authentication. The time factor can also be the systems downfall. If a clock on the system or the password token device becomes out of synch, a user can have troubles authenticating themselves to the system.
Asynchronous Dynamic Password Tokens:
The clock synching problem is eliminated with asynchronous dynamic password tokens. This system works on the same principal as the synchronous one but it does not have a time frame. A lot of big companies use this system especially for employee's who may work from home on the companies VPN (Virtual private
Network).
Challenge Response Tokens:
This is an interesting system. A user will be sent special "challenge" strings at either random or timed intervals. The user inputs this challenge string into their token device and the device will respond by generating a challenge response. The user then types this response into the system and if it is correct they are authenticated.
Reference(s) used for this question:
http://www.informit.com/guides/content.aspx?g=security&seqNum=146 and
KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, 2001, John Wiley & Sons, Page 37.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
user82
10 months, 3 weeks ago
chatgpt. The correct option regarding static password tokens is: D. The token does not authenticate the token owner but the system. In the context of static password tokens, the token itself is typically a physical device or a piece of information (such as a password) that is known to both the user and the system. The user presents the token (e.g., enters the password) to the system, and the system verifies whether the presented token matches the one it expects. So, the token (password in this case) is used by the user to authenticate themselves to the system. The token doesn't authenticate the user; rather, it is used by the user to authenticate to the system.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...