CAS-004 Security Engineering Practice Question
A company is evaluating multi-factor authentication methods. Which TWO are considered phishing-resistant? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FIDO2/WebAuthn
FIDO2/WebAuthn (A) is phishing-resistant because it uses public-key cryptography bound to the origin (relying party ID), so credentials created for one site cannot be replayed on a look-alike phishing domain. Hardware security tokens such as a YubiKey (E) are phishing-resistant for the same reason: they implement FIDO2/U2F and sign a challenge with a private key tied to the legitimate origin, and the private key never leaves the device. In contrast, biometric authentication on a smartphone (B) is only a local verification factor and, by itself, is not bound to the web origin, so it can be captured or relayed in a phishing flow. TOTP via a mobile app (C) is a shared-secret code that a phishing site can proxy in real time, so it is not phishing-resistant. SMS one-time codes (D) are similarly replayable and additionally vulnerable to SIM-swapping and interception, making them the weakest option here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
FIDO2/WebAuthn
Why this is correct
FIDO2/WebAuthn binds credentials to the origin's domain via public-key cryptography, so a phishing site on a different domain cannot trigger or replay the authentication. This origin-binding satisfies the phishing-resistance requirement, unlike OTP or push methods vulnerable to real-time relay.
- ✗
Biometric authentication on a smartphone
Why it's wrong here
Biometric authentication alone is not phishing-resistant; a fingerprint or face check performed on the same channel can be relayed or spoofed, and it is often just a local unlock rather than a bound credential. It suits convenience-focused consumer logins, not high-assurance phishing-resistant MFA.
- ✗
TOTP via mobile app
Why it's wrong here
TOTP codes are phishable: an attacker who proxies the login page in real time can relay the user's typed code and authenticate within its validity window. TOTP is intended for scenarios needing a shared secret on a separate device without hardware tokens, not resistance to real-time relay attacks.
- ✗
SMS one-time codes
Why it's wrong here
SMS one-time codes are phishable and vulnerable to interception, SIM swapping and real-time relay, so they fail the phishing-resistant requirement. They remain useful for low-assurance consumer verification where hardware tokens are impractical, but not for resisting credential phishing.
- ✓
Hardware security tokens (e.g., YubiKey)
Why this is correct
Hardware security tokens implementing FIDO2 store private keys in tamper-resistant hardware and bind assertions to the relying party's origin. Credentials cannot be extracted or replayed to a lookalike domain, making them phishing-resistant by the same cryptographic origin-binding mechanism.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.