All quizzes
Free quiz · 25 questions in the bank

Multi-Factor Authentication quiz

Test your Multi-Factor Authentication knowledge with a free interactive quiz — 25 questions with answers and explanations. No signup needed to play.

Question 1/12Score 0

What has NIST's digital identity guidelines (SP 800-63B) said about SMS-based OTP as an authentication factor?

In this round
  1. What has NIST's digital identity guidelines (SP 800-63B) said about SMS-based OTP as an authentication factor?
  2. Why can unlocking a passkey with a fingerprint or device PIN be considered inherent MFA in a single interaction?
  3. Why is MFA consistently ranked as one of the highest-leverage, lowest-cost security controls an organization can deploy?
  4. What is the core idea behind adaptive (risk-based) authentication?
  5. A password plus a time-based code generated by an authenticator app on the user's phone is an example of combining which two factor categories?
  6. What is the core idea behind multi-factor authentication (MFA)?
  7. What are passkeys, in relation to the WebAuthn standard?
  8. What does TOTP stand for, and what does it use to generate a one-time code?
  9. Why must the TOTP shared secret be stored encrypted at rest on the server, just like a password?
  10. Why must a server compare a submitted TOTP code to the expected code using a timing-safe comparison function?
  11. What is a notable limitation of biometric ("something you are") factors compared to the other factor types?
  12. Where does a WebAuthn/passkey private key reside during authentication?
Gaps to close?
Read the curated Multi-Factor Authentication notes — core concepts, patterns, interview prep.
Multi-Factor Authentication notes

More quizzes

.NETAccessibilityAgile MethodologyAlertmanagerAlgorithmsAndroid