SY0-701 exam dumps

SY0-701 practice question 371 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 371

Single answerPasswordless

A healthcare company is replacing passwords for access to its patient records application because users frequently fall for phishing emails that steal credentials. The security team wants a solution that resists credential replay and phishing, works with modern web applications, and does not require users to remember a shared secret. Which authentication method BEST meets these requirements?

  1. A

    Implement FIDO2/WebAuthn security keys that use public-key cryptography for user authentication

  2. B

    Require users to enter a password plus a six-digit TOTP code from an authenticator app

  3. C

    Send a one-time login link to the user's email address for each sign-in attempt

  4. D

    Issue smart cards but continue requiring users to type their domain passwords at login

Show answer and explanation

Correct answer: A

Explanation

The best answer is FIDO2/WebAuthn security keys because they provide passwordless authentication using public-key cryptography and are designed to be phishing resistant for web applications. Unlike passwords or OTP-based methods, FIDO2 authenticators do not send a reusable shared secret to the application. This significantly reduces the risk of credential theft, replay, and many phishing attacks. Security best practices from organizations such as CISA, NIST, and the FIDO Alliance increasingly recommend phishing-resistant MFA or passwordless methods like FIDO2 for higher-assurance access. By contrast, password plus TOTP remains vulnerable to modern phishing proxies, email-based login links depend on mailbox security, and smart cards that still require passwords do not fully eliminate password-related risk.

  • A. Correct.

    Correct. FIDO2/WebAuthn is a passwordless authentication approach that uses asymmetric cryptography, where the private key remains on the user's authenticator device and the relying party stores only a public key. This helps prevent credential replay because there is no shared password to steal and reuse. It also provides strong phishing resistance because the authenticator validates the legitimate origin before completing authentication. This makes it well suited for modern web applications and aligns with current best practices for passwordless, phishing-resistant authentication.

  • B. Incorrect.

    Incorrect. Password plus TOTP is MFA, but it is not passwordless because users still rely on a memorized secret. It also does not provide the same phishing resistance as FIDO2/WebAuthn. Attackers can capture both the password and the current TOTP code through real-time phishing kits or adversary-in-the-middle attacks and replay them quickly. A candidate might choose this because it is stronger than passwords alone, but it does not fully address the scenario's requirements.

  • C. Incorrect.

    Incorrect. Email magic links can reduce password usage, but they are generally not considered as phishing-resistant as FIDO2/WebAuthn. If the email account is compromised, or if users are tricked into following fraudulent workflows, attackers may still gain access. This approach also depends heavily on the security of the email channel and mailbox rather than providing cryptographic, origin-bound authentication directly to the application.

  • D. Incorrect.

    Incorrect. Smart cards can support strong authentication, but this option explicitly keeps the password requirement, so it is not truly passwordless. In addition, the scenario emphasizes modern web applications and eliminating shared secrets. Requiring continued password entry preserves the phishing and credential-theft risk associated with passwords. Someone might select this because smart cards are strong authenticators, but the retained password makes it a weaker fit for the stated goal.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam