CAS-004 Security Engineering Practice Question
An organization wants to implement passwordless authentication for its employees using FIDO2/WebAuthn. What is a primary security advantage of this approach over traditional password-based MFA?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It is resistant to phishing attacks because credentials are bound to the origin.
FIDO2 uses public key cryptography; the private key never leaves the user's device, so phishing attacks cannot steal credentials. This provides strong resistance to phishing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It is resistant to phishing attacks because credentials are bound to the origin.
Why this is correct
FIDO2/WebAuthn credentials are cryptographically bound to the relying party's origin, so a credential registered for the genuine sign-in endpoint cannot be replayed against a look-alike phishing domain. This origin binding satisfies the stem's passwordless requirement while eliminating credential theft via reverse-proxy phishing kits such as Evilginx, which defeat OTP-based MFA.
- ✗
It eliminates the need for a second factor.
Why it's wrong here
FIDO2/WebAuthn replaces the password with a cryptographic key pair bound to the origin, so the authenticator itself satisfies both possession and verification — it does not remove a factor but removes the shared secret. It is tempting because passwordless flows feel like single-step logins, yet the hardware key still constitutes a possession factor rather than eliminating multi-factor authentication.
- ✗
It allows users to reuse the same credential across multiple websites.
Why it's wrong here
Credential reuse directly undermines FIDO2's design: each credential is scoped to a single relying party's origin, preventing phishing and replay across sites. Reuse is a password weakness, not an advantage. The tempting appeal is convenience, but shared credentials would let one compromised site expose others — the opposite of the isolation WebAuthn enforces.
- ✗
It does not require any client-side hardware.
Why it's wrong here
FIDO2/WebAuthn authenticators are hardware-bound — a security key or platform authenticator with a private key in secure hardware. Claiming no client-side hardware is false; software-only credentials lack that protection. It tempts because some platform authenticators use built-in TPMs, but dedicated roaming keys are still hardware, so the premise fails.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.