- Home
- All questions
- Question 266
CompTIA Security+ study material · question 266 of 611
Which two authenticator types are classed as not phishing-resistant? Choose two.
Show the answer
Answer: B. A one-time password from an authenticator app
D. A code delivered out of band by SMS
Anything the user can read and retype can be relayed to an attacker. Origin-bound cryptographic authenticators cannot.
Source: NIST SP 800-63B Rev. 4 (NIST) — SP 800-63B-4 §§ 3.1.1–3.1.5