Study. uk . com
  1. Home
  2. All questions
  3. Question 281

CompTIA Security+ study material · question 281 of 611

Why is a FIDO2 security key resistant to a convincing look-alike login page?

  1. The key refuses to operate over an untrusted network
  2. The key requires a fingerprint before responding
  3. The key displays the expected domain to the user
  4. The browser binds the assertion to the origin, so a different domain cannot obtain a usable response
Show the answer

Answer: D. The browser binds the assertion to the origin, so a different domain cannot obtain a usable response

Origin binding is what makes the credential unusable on any site other than the one it was registered to.

Source: OWASP Multifactor Authentication Cheat Sheet (OWASP) — OWASP Multifactor Authentication Cheat Sheet › Hardware OTP and FIDO tokens

Challenge yourself on this topic → Study as cards