Study. uk . com
  1. Home
  2. All questions
  3. Question 280

CompTIA Security+ study material · question 280 of 611

Why does adding a security question to a password login not meaningfully improve resistance to credential stuffing?

  1. Users choose the same answer for every site
  2. Security questions cannot be rate limited
  3. Security questions are stored in plaintext
  4. Both are knowledge factors and both are exposed by the same kind of breach
Show the answer

Answer: D. Both are knowledge factors and both are exposed by the same kind of breach

Two prompts of the same category are not multi-factor, so one breach can supply both answers.

Source: OWASP Multifactor Authentication Cheat Sheet (OWASP) — OWASP Multifactor Authentication Cheat Sheet › Factors

Challenge yourself on this topic → Study as cards