Correct Answer: Prioritizing WebAuthn/FIDO2-based phishing-resistant methods where supported, using risk-based adaptive policies to adjust friction by context, incorporating device health checks, and training users to recognize and report suspicious push requests
Explanation: Prioritizing phishing-resistant methods, adaptive risk-based policies, device health checks, and user training together provide strong, low-friction authentication, unlike relying solely on SMS codes, maximizing factors for every login regardless of risk, disabling device health checks, skipping push-bombing training, or applying one fixed policy to every user.
Correct Answer: Prioritizing WebAuthn/FIDO2-based phishing-resistant methods where supported, using risk-based adaptive policies to adjust friction by context, incorporating device health checks, and training users to recognize and report suspicious push requests
Explanation: Prioritizing phishing-resistant methods, adaptive risk-based policies, device health checks, and user training together provide strong, low-friction authentication, unlike relying solely on SMS codes, maximizing factors for every login regardless of risk, disabling device health checks, skipping push-bombing training, or applying one fixed policy to every user.