ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your company ships high-value electronics labeled with passive 13.56 MHz RFID tags so distribution centers can quickly process inbound pallets. Management worries that competitors might discreetly use their own readers alongside public roads to capture tag data in transit and deduce inventory levels. Which design control most effectively mitigates this skimming risk without impeding normal scanning at authorized docks?
Equip the tags with password-protected memory and enforce cryptographic challenge-response between the tag and authorized readers before any data exchange.
Configure readers to transmit at the lowest possible power so tags respond only at very close range.
Switch from high-frequency (13.56 MHz) tags to low-frequency (125 kHz) tags to shorten the read distance and reduce interception chances.
Ship items in metallized, RF-shielded packaging that warehouse staff must remove before scanning each pallet.
Skimming is the unauthorized reading of an RFID tag's data by an attacker's reader. The most effective countermeasure is to ensure tags will communicate only with authenticated, trusted readers. Implementing cryptographic access control-typically a challenge-response protocol where the tag releases data only after verifying that the reader possesses a shared secret key-thwarts unauthorized readers even if they are within range, thereby preserving usability for legitimate warehouse readers. Metallic shielding or "Faraday" packaging can block skimming, but it also blocks authorized scans unless each package is unwrapped, disrupting operations. Simply lowering reader power or moving to low-frequency tags may reduce range but does not prevent a determined attacker with sensitive equipment from eavesdropping or skimming the tag's static identifier. Therefore, employing mutual authentication and encryption on the tag is the most appropriate architectural mitigation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is RFID skimming?
Open an interactive chat with Bash
How does a cryptographic challenge-response protocol work?
Open an interactive chat with Bash
Why is RF-shielded packaging not the best solution for preventing RFID skimming?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .