1. Why has credential theft become the dominant way attackers gain access?
2. Why should the email account be secured before banking or any other service?
3. A victim enters a password and an authenticator app code into a fake page. How does the attack succeed despite the code expiring in thirty seconds?
4. Why does changing your password often fail to remove an attacker who has phished you?
5. What property makes a passkey resistant to phishing?
6. Which of these are genuine weaknesses of SMS based codes? Select all that apply.
7. Given its weaknesses, when is SMS based authentication still the right choice?
8. Why did traditional complexity rules tend to weaken security in practice?
9. Your password manager declines to autofill on a page that looks exactly like your bank. What does this most likely indicate?
10. Why should security question answers be stored random strings rather than truthful ones?