Medium1 markMultiple Choice
Domain 1.2: Authentication and AuthorizationDomain 1PasswordlessAuthenticationFIDO2

AZ-305 · Question 08 · Domain 1.2: Authentication and Authorization

A manufacturing company wants to eliminate passwords for their factory floor workers who access shared kiosks. The workers do not have corporate mobile phones.

You need to recommend a passwordless authentication method that is highly secure, phishing-resistant, and does not require a mobile device.

Which TWO authentication methods meet these requirements? (Select TWO)

Answer options:

A.

Microsoft Authenticator app

B.

FIDO2 security keys

C.

SMS-based authentication

D.

Windows Hello for Business

E.

OATH hardware tokens

How to approach this question

Filter out options that require a mobile phone, then select the true passwordless, phishing-resistant methods.

Full Answer

Microsoft Entra ID supports three primary passwordless authentication methods: Windows Hello for Business, Microsoft Authenticator, and FIDO2 security keys. Since the workers do not have mobile phones, Microsoft Authenticator is excluded. FIDO2 security keys (like YubiKeys) and Windows Hello for Business (using biometrics/PIN on the kiosk) are both highly secure, phishing-resistant, and do not require a mobile device.

Common mistakes

Selecting Microsoft Authenticator out of habit, ignoring the constraint that workers do not have mobile phones.

Practice the full Azure Solutions Architect Expert AZ-305 Practice Exam 2

55 questions · hints · full answers · grading

More questions from this exam