SY0-701 exam dumps

SY0-701 practice question 370 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 370

Single answerPasswordless

A company wants to reduce phishing-related account compromises for employees who access email, HR, and finance applications from managed laptops. The security team is evaluating passwordless authentication methods and wants an option that resists credential phishing and does not rely on users receiving one-time codes by SMS. Which solution BEST meets these requirements?

  1. A

    Deploy FIDO2 security keys that use public key cryptography and require a PIN or biometric on the device

  2. B

    Enable SMS-based one-time passcodes as the primary sign-in method for all users

  3. C

    Require users to create longer passwords and rotate them every 30 days

  4. D

    Use email-based magic links as the standard authentication method for all sensitive applications

Show answer and explanation

Correct answer: A

Explanation

The best choice is FIDO2 security keys because they provide passwordless authentication with strong resistance to phishing. FIDO2, which includes WebAuthn and CTAP, uses asymmetric cryptography so the server stores a public key while the authenticator keeps the private key. Authentication is tied to the legitimate website or application origin, which helps block credential theft through look-alike phishing pages. This aligns with modern best practices promoted by standards bodies such as NIST and the FIDO Alliance. NIST SP 800-63B distinguishes phishing-resistant authentication from weaker methods such as SMS OTP. For sensitive business applications, passwordless methods based on FIDO2 authenticators are generally preferred over SMS codes, frequent password changes, or email magic links.

  • A. Correct.

    Correct. FIDO2 security keys are a strong passwordless option designed to resist phishing. They use public key cryptography, so the private key never leaves the authenticator, and the authentication process is bound to the legitimate relying party. This helps prevent users from being tricked into entering reusable credentials on fake sites. Requiring a local PIN or biometric adds user verification without transmitting a shared secret over the network.

  • B. Incorrect.

    Incorrect. SMS one-time passcodes may remove the password from the workflow, but they are not considered phishing-resistant and are weaker than FIDO2-based methods. SMS is also vulnerable to SIM-swapping, message interception risks, and social engineering. Someone might choose this because it is common and easy to deploy, but it does not meet the stated goal of phishing resistance.

  • C. Incorrect.

    Incorrect. Longer passwords and frequent rotation are password-management controls, not passwordless authentication. They also do not directly solve phishing because users can still be tricked into entering passwords on fraudulent sites. A candidate might select this option because it sounds more secure, but it does not satisfy the passwordless requirement.

  • D. Incorrect.

    Incorrect. Magic links can reduce password use, but they generally depend on the security of the user's email account and are not inherently phishing-resistant for high-risk or sensitive application access. If an attacker compromises email or tricks a user into interacting with a malicious workflow, the account could still be at risk. This makes magic links less appropriate than phishing-resistant authenticators for finance and HR systems.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam