Which term describes a portable hardware security module with a computer interface (USB or NFC) used for multifactor authentication?

Prepare for the Information Security Principles and Frameworks Test. Enhance your understanding with detailed questions, hints, and explanations. Ace your exam with confidence!

Multiple Choice

Which term describes a portable hardware security module with a computer interface (USB or NFC) used for multifactor authentication?

Explanation:
A security key is a portable hardware security token used for multifactor authentication. It’s a small device you carry that plugs into a computer via USB or taps over NFC to prove you possess it during login. The device holds cryptographic keys and, during authentication, signs a challenge from the service using a private key while the service verifies with a public key stored on the server. This creates a strong possession factor and, with modern standards like FIDO2/WebAuthn, is resistant to phishing because the authentication data is bound to the specific origin and requires physical interaction. Smart cards can serve a similar role but usually need a reader and rely on certificates, while biometric methods rely on the user’s physical traits rather than a separate hardware token. The description best fits a security key.

A security key is a portable hardware security token used for multifactor authentication. It’s a small device you carry that plugs into a computer via USB or taps over NFC to prove you possess it during login. The device holds cryptographic keys and, during authentication, signs a challenge from the service using a private key while the service verifies with a public key stored on the server. This creates a strong possession factor and, with modern standards like FIDO2/WebAuthn, is resistant to phishing because the authentication data is bound to the specific origin and requires physical interaction. Smart cards can serve a similar role but usually need a reader and rely on certificates, while biometric methods rely on the user’s physical traits rather than a separate hardware token. The description best fits a security key.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy