CISSP-ISSAP Exam QuestionsBrowse all questions from this exam

CISSP-ISSAP Exam - Question 56


Kerberos is a computer network authentication protocol that allows individuals communicating over a non-secure network to prove their identity to one another in a secure manner. Which of the following statements are true about the Kerberos authentication scheme? Each correct answer represents a complete solution.

Choose all that apply.

Show Answer
Correct Answer: AD

Kerberos requires continuous availability of a central server to manage authentication tasks and prevent security breaches, as it plays a crucial role in the authentication process. Furthermore, synchronized clocks are essential in Kerberos for timestamp validation, preventing replay attacks, and ensuring secure communication. However, dictionary and brute force attacks on the initial TGS response do not reveal subjects' passwords since Kerberos does not transmit passwords between the client and server. The protocol is designed to protect against such vulnerabilities.

Discussion

1 comment
Sign in to comment
ClomirtauyOptions: AD
May 29, 2024

B is false. kerbeos never transmit passwords between client and server