Systems Security Certified Practitioner – SSCP – Question0852

In SSL/TLS protocol, what kind of authentication is supported when you establish a secure session between a client and a server?

A.
Peer-to-peer authentication
B. Only server authentication (optional)
C. Server authentication (mandatory) and client authentication (optional)
D. Role based authentication scheme

Correct Answer: C

Explanation:

RESCORLA, Eric, SSL and TLS: Designing and Building Secure Systems, 2000, Addison Wesley Professional; SMITH, Richard E., Internet Cryptography, 1997, Addison-Wesley Pub Co.