FIDO Compliance, Certification & Interoperability 2 — Questions and Answers
Question 1: Which FIDO Alliance program specifically tests that an authenticator implementation conforms to a published FIDO specification?
- FIDO Functional Certification (Correct answer)
- FIDO Interoperability Testing
- FIDO Ready Program
- FIDO Developer Challenge
Correct answer: FIDO Functional Certification
FIDO Functional Certification verifies that a product correctly implements the FIDO specification requirements.
Question 2: What is the primary purpose of the FIDO Alliance's Authenticator Certification program?
- To market FIDO products to enterprises
- To provide assurance that an authenticator meets FIDO security and interoperability requirements (Correct answer)
- To certify relying party server implementations
- To issue digital certificates for authenticator keys
Correct answer: To provide assurance that an authenticator meets FIDO security and interoperability requirements
The Authenticator Certification program assures buyers that a product meets FIDO's security and interoperability standards.
Question 3: In FIDO2, which component must also be certified for an end-to-end certified ecosystem?
- The operating system kernel
- The client platform (e.g., browser or OS) (Correct answer)
- The TLS certificate authority
- The DNS resolver
Correct answer: The client platform (e.g., browser or OS)
FIDO2 certification covers both the authenticator and the client platform (browser/OS) to ensure full interoperability.
Question 4: Which FIDO certification level specifically requires security evaluation by an accredited third-party laboratory?
- Level 1
- Level 1+
- Level 2 (Correct answer)
- Functional Certification
Correct answer: Level 2
FIDO Authenticator Certification Level 2 (L2) requires evaluation by an accredited security laboratory.
Question 5: What does the FIDO Alliance Metadata Service (MDS) provide to relying parties?
- Real-time revocation of user credentials
- Metadata about certified authenticators including their security characteristics (Correct answer)
- A directory of registered FIDO users
- Public keys for FIDO server certificates
Correct answer: Metadata about certified authenticators including their security characteristics
MDS provides relying parties with up-to-date metadata about certified authenticators, including their capabilities and certification status.
Question 6: Which specification governs FIDO UAF authenticator commands used in the certification testing process?
- FIDO UAF Authenticator Commands specification (Correct answer)
- FIDO UAF Protocol specification
- FIDO UAF Application API specification
- FIDO UAF Authenticator Transport Binding specification
Correct answer: FIDO UAF Authenticator Commands specification
The FIDO UAF Authenticator Commands specification defines the low-level commands used to communicate with UAF authenticators, which are tested during certification.
Question 7: A vendor wants to re-use a previously certified authenticator module in a new product. What must they do according to FIDO Alliance certification rules?
- No additional steps are needed; the certification transfers automatically
- File a derivative certification request and pay applicable fees (Correct answer)
- Repeat the full certification process from scratch
- Only update the metadata entry without retesting
Correct answer: File a derivative certification request and pay applicable fees
FIDO Alliance allows derivative certifications for products re-using certified modules, requiring a formal request and applicable fees rather than a full re-test.
Which FIDO Alliance program specifically tests that an authenticator implementation conforms to a published FIDO specification?