Courseiva
Security Engineering →mediumMultiple Select

CAS-004 Security Engineering Practice Question

A company is evaluating multi-factor authentication methods. Which TWO are considered phishing-resistant? (Select TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

FIDO2/WebAuthn

FIDO2/WebAuthn (A) is phishing-resistant because it uses public-key cryptography bound to the origin (relying party ID), so credentials created for one site cannot be replayed on a look-alike phishing domain. Hardware security tokens such as a YubiKey (E) are phishing-resistant for the same reason: they implement FIDO2/U2F and sign a challenge with a private key tied to the legitimate origin, and the private key never leaves the device. In contrast, biometric authentication on a smartphone (B) is only a local verification factor and, by itself, is not bound to the web origin, so it can be captured or relayed in a phishing flow. TOTP via a mobile app (C) is a shared-secret code that a phishing site can proxy in real time, so it is not phishing-resistant. SMS one-time codes (D) are similarly replayable and additionally vulnerable to SIM-swapping and interception, making them the weakest option here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    FIDO2/WebAuthn

    Why this is correct

    FIDO2/WebAuthn binds credentials to the origin's domain via public-key cryptography, so a phishing site on a different domain cannot trigger or replay the authentication. This origin-binding satisfies the phishing-resistance requirement, unlike OTP or push methods vulnerable to real-time relay.

  • ✗

    Biometric authentication on a smartphone

    Why it's wrong here

    Biometric authentication alone is not phishing-resistant; a fingerprint or face check performed on the same channel can be relayed or spoofed, and it is often just a local unlock rather than a bound credential. It suits convenience-focused consumer logins, not high-assurance phishing-resistant MFA.

  • ✗

    TOTP via mobile app

    Why it's wrong here

    TOTP codes are phishable: an attacker who proxies the login page in real time can relay the user's typed code and authenticate within its validity window. TOTP is intended for scenarios needing a shared secret on a separate device without hardware tokens, not resistance to real-time relay attacks.

  • ✗

    SMS one-time codes

    Why it's wrong here

    SMS one-time codes are phishable and vulnerable to interception, SIM swapping and real-time relay, so they fail the phishing-resistant requirement. They remain useful for low-assurance consumer verification where hardware tokens are impractical, but not for resisting credential phishing.

  • ✓

    Hardware security tokens (e.g., YubiKey)

    Why this is correct

    Hardware security tokens implementing FIDO2 store private keys in tamper-resistant hardware and bind assertions to the relying party's origin. Credentials cannot be extracted or replayed to a lookalike domain, making them phishing-resistant by the same cryptographic origin-binding mechanism.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.