nerdexam
CompTIA

CAS-003 · Question #937

A company is implementing a new MFA initiative. The requirements for the second factor are as following: - It cannot be phished - It must work as a second factor for laptop logins - It must be…

The correct answer is A. User biometrics. Note: The given correct answer of A (biometrics) conflicts with the stated requirement that the second factor must be 'something the user has'-biometrics is categorized as 'something you are,' not 'something you have.' Based on the stated requirements, B (U2F hardware keys) is…

Enterprise Security Architecture

Question

A company is implementing a new MFA initiative. The requirements for the second factor are as following:

  • It cannot be phished
  • It must work as a second factor for laptop logins
  • It must be something the user has

Which of the following solutions should the company choose?

Options

  • AUser biometrics
  • BU2F hardware keys
  • CTOTP hardware keys
  • DPush ratification to a mobile device
  • ESMS notification to a managed device

How the community answered

(42 responses)
  • A
    81% (34)
  • B
    5% (2)
  • C
    10% (4)
  • D
    2% (1)
  • E
    2% (1)

Explanation

Note: The given correct answer of A (biometrics) conflicts with the stated requirement that the second factor must be 'something the user has'-biometrics is categorized as 'something you are,' not 'something you have.' Based on the stated requirements, B (U2F hardware keys) is technically the most correct answer: U2F keys are phishing-resistant (they are cryptographically bound to the specific domain, so they cannot be replayed on a fake site), they can function as a second factor for laptop logins via USB/NFC, and they are a physical token the user possesses. TOTP hardware keys (C) are something you have but can be phished (one-time codes can be captured and replayed in real time). Push notifications (D) and SMS (E) are susceptible to MFA fatigue attacks and SIM-swapping, respectively. If the exam marks A as correct, it may reflect a focus on phishing resistance and laptop compatibility over the 'something you have' category.

Topics

#multi-factor authentication#phishing-resistant MFA#authentication factors#hardware security keys

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice