ISC2 CISSP Practice Question

Under the NIST SP 800-63B Digital Identity Guidelines, organizations that wish to use biometric authentication must follow specific constraints. Which of the following statements correctly reflects those requirements?

  • Biometrics can serve as the sole factor for any authentication assurance level once the sensor meets a false-match rate of 1 in 10,000.

  • Biometrics may be used only as one factor in a multi-factor scheme that includes something you have, and users must be offered a non-biometric alternative.

  • Federal agencies are prohibited from employing biometrics for remote user authentication because biometric data is considered sensitive PII.

  • Once a biometric factor is deployed, organizations are not required to provide any alternative authentication mechanism unless the biometric system fails.

ISC2 CISSP
Identity and Access Management (IAM)
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot