Questions: Two-Factor Authentication

5 questions to test your understanding

Score: 0 / 5
Question 1 Multiple Choice

An attacker obtains your password through a data breach and then uses social engineering to convince your phone carrier to transfer your number to a SIM card they control. Which 2FA method would still protect your account from this attack?

ASMS-based 2FA — your number is registered to your account
BAn authenticator app that generates time-based codes on your phone
CA hardware security key
DBoth authenticator apps and hardware keys would protect you equally
Question 2 Multiple Choice

Which 2FA method is the only one that provides protection if you accidentally enter your credentials on a convincing phishing site?

ASMS-based 2FA, because the attacker would also need your phone
BAn authenticator app, because the TOTP code expires within 30 seconds
CA hardware security key, because it authenticates against the website's cryptographic identity and will not work on a fake site
DAny 2FA method protects against phishing, since the attacker would need both your password and second factor
Question 3 True / False

SMS-based two-factor authentication can be defeated by a SIM-swapping attack, even though it requires something you 'have' (your phone number).

TTrue
FFalse
Question 4 True / False

Two-factor authentication protects your account even if you enter both your password and your 2FA code on a phishing site, because the attacker still doesn't have your physical second factor.

TTrue
FFalse
Question 5 Short Answer

Recovery codes are sometimes described as 'equally powerful' to your 2FA device itself. Explain why this is true and what it means for how you should store them.

Think about your answer, then reveal below.