Two-factor authentication (2FA) completely eliminates the risk of account compromise.
- True
- False
Answer: False
2FA significantly reduces risk but doesn't eliminate it. Attackers can bypass 2FA via SIM swapping, phishing for OTPs, malware capturing tokens, or social engineering. Best practice: use authenticator apps or hardware tokens instead of SMS, monitor account activity, and use unique passwords.