Soru

Zorluk: OrtaPassword Security Policies, MFA, and Certificates

A network security administrator is configuring digital certificate services and Multi-Factor Authentication (MFA) to secure management sessions on enterprise network infrastructure. Which of the following statements accurately describe digital certificate verification and MFA factor rules? (Select TWO.)

  1. The verifying client validates the Certificate Authority (CA) digital signature on a presented certificate by using the public key of the issuing CA.Cevap
  2. B
    A Certificate Signing Request (CSR) generated by an edge router embeds the root CA's private key to encrypt administrative TACACS+ authentication payloads.
  3. Effective Multi-Factor Authentication requires combining credentials from at least two distinct factor categories, such as a passphrase and a hardware OTP token.Cevap
  4. D
    Enabling a local password complexity policy automatically commits all user credentials directly into the device startup-config without explicit administrator command execution.
  5. E
    Certificate Revocation Lists (CRLs) require an explicit deny statement in a local IPv4 ACL to block connections from revoked certificate serial numbers.

Cevap

The correct statements are that certificate verification requires validating the CA's digital signature using the CA's public key, and that MFA requires combining credentials from at least two distinct authentication factor categories (such as a passphrase and an OTP token).
Verifying a digital certificate involves checking the issuing CA's signature using that CA's public key. For MFA, authentication requires at least two independent factor types (such as something you know combined with something you have).

Adım Adım Çözüm

1
Analyze certificate validation mechanics.
Digital certificates are signed by a trusted Certificate Authority (CA). Receivers verify the validity of the signature using the CA's public key.
This establishes the chain of trust in Public Key Infrastructure (PKI).
2
Analyze Multi-Factor Authentication (MFA) requirements.
MFA requires combining factors from different categories (Knowledge, Possession, Inherence). Combining a passphrase (something you know) with a hardware token (something you have) fulfills MFA requirements.
Using two items from the same category (e.g., two passwords) is multi-step authentication, not multi-factor authentication.

Anahtar Kavram

PKI Certificate Verification and MFA Authentication Factor Requirements
Bu soruyu puanla