Multi-factor authentication (MFA) using SMS-based OTP is considered the most secure MFA method.
- True
- False
Answer: False
SMS-based OTP is vulnerable to SIM swapping, SS7 attacks, and phishing. More secure MFA methods include: authenticator apps (TOTP), hardware tokens (YubiKey), biometrics, and FIDO2/WebAuthn. NIST guidelines recommend moving away from SMS OTP for high-security applications. Layered security approach is essential.