shieldCISSP Practice Domain 5 — Identity and Access Management (IAM) Q87 of 120

Which technique provides MFA without sending codes over SMS?

A CISSP practice question covering Domain 5: Identity and Access Management (IAM). Try answering before reading the explanation below.

Show options & answer
A
TOTP via authenticator app or hardware key (FIDO2/WebAuthn)
✓ Correct answer
B
Phone number verification only
C
Email link only
D
Knowledge-based questions
Why "TOTP via authenticator app or hardware key (FIDO2/WebAuthn)" is the right answer

TOTP and FIDO2/WebAuthn keys avoid SIM-swap risk. SMS is no longer recommended for high-value accounts. Email links are weaker than TOTP. Knowledge-based questions are widely regarded as ineffective.

Study videos for this topic

Want to go deeper on Domain 5? Watch the full breakdown — every video is free, no account, no upsell.

Take the full CISSP practice test
120 questions, instant explanations, study-video links on every miss. No account.
Start full test →