CAS-003 · Question #937
A company is implementing a new MFA initiative. The requirements for the second factor are as following: - It cannot be phished - It must work as a second factor for laptop logins - It must be…
The correct answer is A. User biometrics. Note: The given correct answer of A (biometrics) conflicts with the stated requirement that the second factor must be 'something the user has'-biometrics is categorized as 'something you are,' not 'something you have.' Based on the stated requirements, B (U2F hardware keys) is…
Question
A company is implementing a new MFA initiative. The requirements for the second factor are as following:
- It cannot be phished
- It must work as a second factor for laptop logins
- It must be something the user has
Which of the following solutions should the company choose?
Options
- AUser biometrics
- BU2F hardware keys
- CTOTP hardware keys
- DPush ratification to a mobile device
- ESMS notification to a managed device
How the community answered
(42 responses)- A81% (34)
- B5% (2)
- C10% (4)
- D2% (1)
- E2% (1)
Explanation
Note: The given correct answer of A (biometrics) conflicts with the stated requirement that the second factor must be 'something the user has'-biometrics is categorized as 'something you are,' not 'something you have.' Based on the stated requirements, B (U2F hardware keys) is technically the most correct answer: U2F keys are phishing-resistant (they are cryptographically bound to the specific domain, so they cannot be replayed on a fake site), they can function as a second factor for laptop logins via USB/NFC, and they are a physical token the user possesses. TOTP hardware keys (C) are something you have but can be phished (one-time codes can be captured and replayed in real time). Push notifications (D) and SMS (E) are susceptible to MFA fatigue attacks and SIM-swapping, respectively. If the exam marks A as correct, it may reflect a focus on phishing resistance and laptop compatibility over the 'something you have' category.
Topics
Community Discussion
No community discussion yet for this question.