Study. uk . com
  1. Home
  2. All questions
  3. Question 266

CompTIA Security+ study material · question 266 of 611

Which two authenticator types are classed as not phishing-resistant? Choose two.

  1. A multi-factor cryptographic authenticator with a bound origin
  2. A one-time password from an authenticator app
  3. A FIDO2 security key
  4. A code delivered out of band by SMS
Show the answer

Answer: B. A one-time password from an authenticator app
D. A code delivered out of band by SMS

Anything the user can read and retype can be relayed to an attacker. Origin-bound cryptographic authenticators cannot.

Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 §§ 3.1.1–3.1.5

Challenge yourself on this topic → Study as cards