Which control defeats credential phishing even when the user is successfully fooled?
- A Phishing-resistant MFA such as FIDO2 security keys
- B SMS one-time codes
- C A longer password policy
- D Email attachment scanning
Answer
Phishing-resistant MFA such as FIDO2 security keys
FIDO2 binds authentication to the legitimate origin, so credentials captured on a lookalike site cannot be replayed.





