AZ-500 Secure identity and access Practice Question
You are designing a Microsoft Entra ID tenant for a multinational organization. The security team requires that all administrative users must use phishing-resistant MFA. Administrators are located in different regions and may use different devices. Which MFA method should you enforce?
⚠ Common exam trap
Test-takers frequently confuse 'multi-factor authentication' with 'phishing-resistant MFA', and select Microsoft Authenticator with OTP because it is a common MFA method, but it does not protect against real-time phishing attacks where the OTP is captured and replayed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FIDO2 security keys
FIDO2 security keys are the only option that provides phishing-resistant MFA, as they use public-key cryptography and are bound to a specific web origin, preventing credential theft via man-in-the-middle attacks. This satisfies the security team's requirement for all administrative users, regardless of region or device, because FIDO2 keys are hardware-based and interoperable across platforms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
FIDO2 security keys
Why this is correct
FIDO2 security keys are phishing-resistant because they use public-key cryptography where the private key never leaves the device and authentication is bound to the exact relying party origin. During a phishing attack, the key’s challenge-response only works for the legitimate site’s domain, so the credential cannot be relayed to a malicious impersonator. This eliminates shared secrets and prevents man-in-the-middle relay attacks, making it a strong authenticator for Microsoft Entra ID.
- ✗
SMS-based verification
Why it's wrong here
SMS-based verification is not phishing-resistant because it delivers a one-time code over text, which can be intercepted via SIM swapping, SS7 vulnerabilities, or malicious apps on the user’s device. Moreover, the code is a shared secret that a victim can be tricked into typing into a fake sign-in page, allowing the attacker to relay it to the authentic service in real time. While convenient, SMS lacks origin binding, so it cannot protect against targeted phishing.
- ✗
Phone call verification
Why it's wrong here
Phone call verification shares SMS’s lack of phishing resistance, but with distinct attack vectors: attackers can redirect call forwarding or port the phone number, and users may be socially engineered into reading the voice-delivered code aloud. The code itself is still a shared secret, and since the user has no way to verify the genuine Microsoft service on the other end, the code can be captured in a vishing or call spoofing scenario. This interactive method also suffers from the same lack of cryptographic origin binding, leaving it vulnerable to interception and relay.
- ✗
Microsoft Authenticator with OTP
Why it's wrong here
Microsoft Authenticator with OTP (time-based one-time password) is phishing-susceptible because TOTP codes are derived from a shared secret stored in the authenticator app, and the code can be phished just like a password. In a real-time phishing attack, the user enters the current six-digit code on a malicious site, which immediately forwards it to the legitimate Microsoft login, allowing the attacker to complete authentication. Because the OTP is not cryptographically tied to the origin, any page that asks for the code can capture it, making this method vulnerable to man-in-the-middle and relay attacks.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.