Which authentication uses a separate communication channel to deliver the OTP or PIN?

Study for the CompTIA SecurityX Test. Equip yourself with comprehensive flashcards and multiple choice questions that include hints and explanations. Gear up for your certification exam!

Multiple Choice

Which authentication uses a separate communication channel to deliver the OTP or PIN?

Explanation:
Out-of-band authentication relies on delivering the one-time password or PIN through a channel separate from the one used to initiate the login. For example, you might enter your username on a web page, and the system sends an OTP via SMS to your phone or via a hardware token or voice call. This separate path makes it harder for an attacker who is capturing traffic on the primary channel to obtain the OTP, increasing security. In-band authentication, by contrast, delivers the OTP through the same channel used for the login request—for instance, within the same web page or app session. TACACS+ and RADIUS are authentication protocols that manage credentials and access control, not specifically about delivering OTPs via a separate channel, so they don’t fit the concept described.

Out-of-band authentication relies on delivering the one-time password or PIN through a channel separate from the one used to initiate the login. For example, you might enter your username on a web page, and the system sends an OTP via SMS to your phone or via a hardware token or voice call. This separate path makes it harder for an attacker who is capturing traffic on the primary channel to obtain the OTP, increasing security.

In-band authentication, by contrast, delivers the OTP through the same channel used for the login request—for instance, within the same web page or app session.

TACACS+ and RADIUS are authentication protocols that manage credentials and access control, not specifically about delivering OTPs via a separate channel, so they don’t fit the concept described.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy