Help-desk phishing calls successfully harvest SMS one-time passcodes from city employees. Which authentication direction best reduces that risk where feasible?
Select an answer to reveal the explanation.
Short Explanation
If a fake help desk can sweet-talk the text-message code out of someone, SMS OTP is on thin ice. Move toward keys and platform authenticators that do not hand a code to a stranger on the phone.
Full Explanation
SMS OTP is vulnerable to social engineering, SIM swap, and interception. Phishing-resistant authenticators (FIDO2/WebAuthn security keys or comparable platform authenticators) bind authentication to the legitimate origin and avoid transferable OTP codes. Knowledge-based questions are weak; removing MFA increases account-takeover risk. CISSP expects favoring stronger factors when operationally feasible.