FIDO Cheat Sheet 2026
The 30 highest-yield FIDO facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
0 questions
0 min time limit
0% to pass
- What are potential consequences of regulatory non-compliance for FIDO Certified Authenticator professionals? → Fines, license revocation, legal liability, and reputational damage
- An authenticator supports 'alwaysUv'. What does this flag indicate? → The authenticator always requires user verification, even for discoverable credentials
- In FIDO2, what does the 'uv' flag in the authenticator data (authData) indicate? → The authenticator performed user verification during the operation
- What does the FIDO Metadata Service (MDS) provide to relying parties? → Trustworthy metadata about certified authenticator models
- A healthcare provider wants FIDO authentication but requires that private keys never leave hardware. Which authenticator category satisfies this requirement? → Roaming authenticators with hardware-backed secure elements
- Which attestation format wraps the authenticator's attestation statement inside an X.509 certificate chain rooted at the FIDO Alliance MDS? → packed
- What is the significance of the 'aaguid' field in a FIDO2 authenticator? → It uniquely identifies the authenticator model and manufacturer
- What does 'credProtect' extension level 3 enforce on a FIDO2 authenticator? → User verification is required before any credential metadata is revealed
- Which FIDO certification focuses on ensuring that products from different vendors work together correctly in realistic end-to-end scenarios? → FIDO Interoperability Certification
- Which FIDO2 feature allows a credential to be backed up and restored across devices? → Discoverable credentials with the BE flag set
- A meta-analysis of FIDO phishing-resistance studies reports a pooled odds ratio of 0.02 compared to passwords. What does this finding mean? → FIDO users are 98% less likely to be successfully phished than password users
- What is the purpose of the 'prf' (Pseudo-Random Function) FIDO2 extension? → To derive symmetric keys from a credential for use by the relying party's application
- What does the 'origin' field in a WebAuthn ceremony protect against? → Phishing attacks
- Which cryptographic primitive is used by FIDO2 authenticators to prove possession of a private key without revealing it? → Digital signature
- Which of the following is NOT one of the defined WebAuthn attestation statement formats? → fido-u2f-legacy
- What is the significance of a code of ethics for FIDO professionals? → It establishes expected behaviors that protect both the public and the profession
- Under FIDO's approach to biometric privacy, which statement best describes how biometric data is treated across different relying parties? → Biometric data stays on the device and is never sent to any relying party
- Which FIDO Alliance document defines the conformance testing procedures that authenticators must pass for certification? → FIDO Authenticator Security Requirements
- What is the primary purpose of regulatory compliance in FIDO Certified Authenticator practice? → To protect public safety and maintain professional accountability
- Which FIDO certification level specifically requires security evaluation by an accredited third-party laboratory? → Level 2
- What is a risk register used for in FIDO Certified Authenticator practice? → Tracking identified risks with their status, controls, and owners
- Which sampling method is most appropriate when researching FIDO adoption across heterogeneous enterprise sectors? → Stratified random sampling by industry sector
- What enables compatibility among certified devices? → Standardized protocols
- A client asks why FIDO2 is more secure than SMS-based OTP. What is the most accurate explanation to provide? → FIDO2 uses public-key cryptography so credentials never leave the device
- Which CTAP2 command is used by a platform to retrieve a list of credentials stored on an authenticator? → authenticatorCredentialManagement
- Which body accredits the testing laboratories authorized to perform FIDO security evaluations? → The FIDO Alliance directly
- Which CTAP2 command would a platform use to enumerate all discoverable credentials stored on an authenticator? → authenticatorCredentialManagement with enumerateCredentials
- Which FIDO MDS (Metadata Service) data type is used to determine if an authenticator model has been revoked? → statusReports containing REVOKED status
- Which transport protocol introduced in CTAP2.1 allows authenticators to initiate communication? → Hybrid (caBLE)
- A relying party wants to accept only hardware security keys, not platform authenticators. Which WebAuthn parameter should it set? → authenticatorAttachment: 'cross-platform'
Turn these facts into recall:
Was this helpful?