- Home
- All questions
- Question 281
CompTIA Security+ study material · question 281 of 611
Why is a FIDO2 security key resistant to a convincing look-alike login page?
Show the answer
Answer: D. The browser binds the assertion to the origin, so a different domain cannot obtain a usable response
Origin binding is what makes the credential unusable on any site other than the one it was registered to.
Source: OWASP Multifactor Authentication Cheat Sheet (OWASP) — OWASP Multifactor Authentication Cheat Sheet › Hardware OTP and FIDO tokens