All quizzes
Free quiz · 25 questions in the bank

Multi-Factor Authentication quiz

Test your Multi-Factor Authentication knowledge with a free interactive quiz — 25 questions with answers and explanations. No signup needed to play.

Question 1/12Score 0

Where does a WebAuthn/passkey private key reside during authentication?

In this round
  1. Where does a WebAuthn/passkey private key reside during authentication?
  2. Beyond SIM swapping, what other structural weakness makes SMS OTP the weakest widely-deployed MFA method?
  3. Why is MFA consistently ranked as one of the highest-leverage, lowest-cost security controls an organization can deploy?
  4. What has NIST's digital identity guidelines (SP 800-63B) said about SMS-based OTP as an authentication factor?
  5. A password plus a time-based code generated by an authenticator app on the user's phone is an example of combining which two factor categories?
  6. What is a notable limitation of biometric ("something you are") factors compared to the other factor types?
  7. Why do TOTP verification implementations typically accept the current time window plus one window before and after, rather than only the exact current window?
  8. What does TOTP stand for, and what does it use to generate a one-time code?
  9. Which of these is an example of a "something you have" (possession) authentication factor?
  10. How does WebAuthn authentication fundamentally differ from password- or OTP-based authentication?
  11. How does "number matching" mitigate MFA fatigue / push-bombing attacks?
  12. Why can unlocking a passkey with a fingerprint or device PIN be considered inherent MFA in a single interaction?
Gaps to close?
Read the curated Multi-Factor Authentication notes — core concepts, patterns, interview prep.
Multi-Factor Authentication notes

More quizzes

.NET.NET MAUIAbsintheAccessibilityActixActix Web