- Home
- All questions
- Question 280
CompTIA Security+ study material · question 280 of 611
Why does adding a security question to a password login not meaningfully improve resistance to credential stuffing?
Show the answer
Answer: D. Both are knowledge factors and both are exposed by the same kind of breach
Two prompts of the same category are not multi-factor, so one breach can supply both answers.
Source: OWASP Multifactor Authentication Cheat Sheet (OWASP) — OWASP Multifactor Authentication Cheat Sheet › Factors