A client is setting up multi-factor authentication (MFA). Which MFA method is considered MOST secure?
-
A
SMS text message codes sent to a mobile phone
-
B
Security questions based on personal history
-
C
A hardware security key (e.g., FIDO2/YubiKey)
-
D
An email-based one-time passcode