ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 280 - SY0-701 discussion

Report
Export

Which of the following best describes why me SMS DIP authentication method is more risky to implement than the TOTP method?

A.
The SMS OTP method requires an end user to have an active mobile telephone service and SIM card.
Answers
A.
The SMS OTP method requires an end user to have an active mobile telephone service and SIM card.
B.
Generally. SMS OTP codes are valid for up to 15 minutes while the TOTP time frame is 30 to 60 seconds
Answers
B.
Generally. SMS OTP codes are valid for up to 15 minutes while the TOTP time frame is 30 to 60 seconds
C.
The SMS OTP is more likely to be intercepted and lead to unauthorized disclosure of the code than the TOTP method.
Answers
C.
The SMS OTP is more likely to be intercepted and lead to unauthorized disclosure of the code than the TOTP method.
D.
The algorithm used to generate on SMS OTP code is weaker than the one used to generate a TOTP code
Answers
D.
The algorithm used to generate on SMS OTP code is weaker than the one used to generate a TOTP code
Suggested answer: C

Explanation:

The SMS OTP (One-Time Password) method is more vulnerable to interception compared to TOTP (Time-based One-Time Password) because SMS messages can be intercepted through various attack vectors like SIM swapping or SMS phishing. TOTP, on the other hand, generates codes directly on the device and does not rely on a communication channel like SMS, making it less susceptible to interception.

Reference = CompTIA Security+ SY0-701 study materials, particularly in the domain of identity and access management.

===============

asked 02/10/2024
David Shokrai
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first