Question

The establishment of a KNX IP Secure session uses the MIKEY protocol (Multimedia Internet KEYing) to negotiate the symmetric session key, building on the long-term keys stored in the ETS keyring.

KNX AdvancedMock examKNX Secure (extra-syllabus)Hard
Answer

True

MIKEY, adapted to the KNX IP Secure context (based on RFC 3830), provides authenticated key establishment with mutual authentication. The Pre-Master Keys (PMK) are derived from the project keyring, and the current session is then protected with AES-128 CCM. Compromising one session does not compromise the others (partial forward secrecy).

Preparation tip

Treat the ETS keyring file as a high-value secret — anyone with the keyring can transparently re-open sessions on every Secure device of the project.

Full bank

Keep going with the full KNX Advanced bank

Keep going with the full KNX Advanced bank: unlimited timed mock exams, detailed answers, history. From €9 (one-time payment).

See pricing — from €9
Want more?

See the 9 other KNX Advanced practice questions

Related questions

Question from our independent practice bank. KNX Advanced is a registered trademark of KNX Association, not affiliated with CertifBus.

Last updated: 19 May 2026

See pricing — from €9
KNX Advanced pack · from €9
KNX BASIC & ADVANCED

Ready to find out where you really stand?

10 free questions every day, no account needed. Full access only if you decide to go all the way.

+1/−0,5 official scoringFR·EN·DE interface and explanations9 from · one-time payment
Newsletter

Get launch announcements

We'll email you when a new bank ships (BACnet, Modbus, etc.) or a new tool. Plus an early-bird discount on first purchases. No spam.

Unsubscribe in 1 click. No sharing with third parties.