Question

Matter defines two secure-channel modes: PASE (Password Authenticated Session Establishment), used during commissioning with the Setup PIN as a shared secret, and CASE (Certificate Authenticated Session Establishment), used post-commissioning with mutual X.509 certificates.

MatterMock examCommissioningHard
Answer

True

Matter security is split into two phases. PASE runs only during initial commissioning: it uses a SPAKE2+ password handshake with the Setup PIN as a one-time shared secret and is never used again once the device is provisioned. CASE then takes over for all runtime traffic: each device and each administrator holds X.509 Node Operational Certificates issued by the fabric's Certification Authority, and CASE performs mutual authentication on every session. The underlying primitives are modern: ECDH on the P-256 curve, AES-128-CCM for symmetric encryption and SHA-256 for hashing.

Preparation tip

If commissioning succeeds but the device later refuses to talk to the controller, the failure is on the CASE side (certificate or fabric trust), not on the PASE side; resetting the Setup PIN will not help.

Waitlist

Matter bank in preparation

The full Matter bank isn't available yet. Drop your email to get notified at launch and grab an early-bird discount.

Join the waitlist
Want more?

See the 9 other Matter practice questions

Related questions

Question from our independent practice bank. Matter is a registered trademark of Connectivity Standards Alliance, not affiliated with CertifBus.

Last updated: 19 May 2026

Join the waitlist
Matter waitlist