← Security+ glossary

Identity and access management (IAM)

Phishing-resistant authentication

A form of strong authentication, typically FIDO2/WebAuthn with a hardware security key, that uses public-key cryptography bound to the exact domain of the website. It is resistant to phishing because the secret key never leaves the device and nothing interceptable is entered, unlike SMS and ordinary OTP codes that can be intercepted or redirected to a fake page.

All Security+ guides →

Related terms

Get CertOwl on the App Store

Free download · A+ and Network+ completely free
+ daily lessons, flashcards and full exam simulations