問題文
A bank wants a transaction test to sign in to its own portal, which is protected by single sign-on with a second factor. Which of these second factors does the documentation place outside what a browser synthetics test can carry out?
選択肢
- A hardware one-time-password token such as a SecurID device, which sits in the same list as push notification apps, WebAuthn, client certificates and image CAPTCHAs.
- A time-based one-time password generated from a shared secret, which sits in the same list as push notification apps, WebAuthn, client certificates and image CAPTCHAs.
- A challenge-response exchange against a Windows identity provider, which sits in the same list as push notification apps, WebAuthn, client certificates and image CAPTCHAs.
- A text-based arithmetic CAPTCHA on the login page, which sits in the same list as push notification apps, WebAuthn, client certificates and image CAPTCHAs.