CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security architect is designing an authentication system for a new enterprise application that requires high assurance and resistance to credential stuffing attacks. The system must support multi-factor authentication (MFA) and provide cryptographic proof of identity without relying on shared secrets or centralized user databases for primary authentication. Which of the following authentication standards would BEST meet these requirements?

  1. ASAML 2.0
  2. BFIDO2
  3. COAuth 2.0
  4. DOpenID Connect
Show answer & explanation

Correct answer: B. FIDO2

FIDO2 (Fast Identity Online 2) is specifically designed to provide strong, phishing-resistant, passwordless authentication using public-key cryptography. It leverages WebAuthn and CTAP2 protocols to offer cryptographic proof of identity without shared secrets, directly addressing the requirements for high assurance and resistance to credential stuffing.

Why the other options are wrong

  • A. SAML 2.0 is an XML-based standard for exchanging authentication and authorization data, primarily used for single sign-on (SSO), but it doesn't intrinsically provide phishing resistance or passwordless authentication like FIDO2.
  • C. OAuth 2.0 is an authorization framework, not an authentication standard, and does not inherently provide strong authentication or phishing resistance.
  • D. OpenID Connect is an identity layer on top of OAuth 2.0, providing identity verification, but it relies on traditional authentication methods like passwords and does not inherently offer FIDO2's level of phishing resistance or passwordless capabilities.

FIDO2

FIDO2 is an open authentication standard that enables users to leverage common devices to easily and securely authenticate to online services in place of passwords, offering phishing-resistant authentication.

  • Uses public-key cryptography for strong authentication.
  • Supports passwordless authentication.
  • Highly resistant to phishing and credential stuffing attacks.
  • Comprises WebAuthn (for browsers/platforms) and CTAP2 (for authenticators).

Memory trick: FIDO's Fast Identity Defeats Phishing Online

More Security Engineering questions