FIDO Cheat Sheet 2026

The 30 highest-yield FIDO facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

0 questions
0 min time limit
0% to pass
  1. What are potential consequences of regulatory non-compliance for FIDO Certified Authenticator professionals? Fines, license revocation, legal liability, and reputational damage
  2. An authenticator supports 'alwaysUv'. What does this flag indicate? The authenticator always requires user verification, even for discoverable credentials
  3. In FIDO2, what does the 'uv' flag in the authenticator data (authData) indicate? The authenticator performed user verification during the operation
  4. What does the FIDO Metadata Service (MDS) provide to relying parties? Trustworthy metadata about certified authenticator models
  5. A healthcare provider wants FIDO authentication but requires that private keys never leave hardware. Which authenticator category satisfies this requirement? Roaming authenticators with hardware-backed secure elements
  6. Which attestation format wraps the authenticator's attestation statement inside an X.509 certificate chain rooted at the FIDO Alliance MDS? packed
  7. What is the significance of the 'aaguid' field in a FIDO2 authenticator? It uniquely identifies the authenticator model and manufacturer
  8. What does 'credProtect' extension level 3 enforce on a FIDO2 authenticator? User verification is required before any credential metadata is revealed
  9. Which FIDO certification focuses on ensuring that products from different vendors work together correctly in realistic end-to-end scenarios? FIDO Interoperability Certification
  10. Which FIDO2 feature allows a credential to be backed up and restored across devices? Discoverable credentials with the BE flag set
  11. A meta-analysis of FIDO phishing-resistance studies reports a pooled odds ratio of 0.02 compared to passwords. What does this finding mean? FIDO users are 98% less likely to be successfully phished than password users
  12. What is the purpose of the 'prf' (Pseudo-Random Function) FIDO2 extension? To derive symmetric keys from a credential for use by the relying party's application
  13. What does the 'origin' field in a WebAuthn ceremony protect against? Phishing attacks
  14. Which cryptographic primitive is used by FIDO2 authenticators to prove possession of a private key without revealing it? Digital signature
  15. Which of the following is NOT one of the defined WebAuthn attestation statement formats? fido-u2f-legacy
  16. What is the significance of a code of ethics for FIDO professionals? It establishes expected behaviors that protect both the public and the profession
  17. Under FIDO's approach to biometric privacy, which statement best describes how biometric data is treated across different relying parties? Biometric data stays on the device and is never sent to any relying party
  18. Which FIDO Alliance document defines the conformance testing procedures that authenticators must pass for certification? FIDO Authenticator Security Requirements
  19. What is the primary purpose of regulatory compliance in FIDO Certified Authenticator practice? To protect public safety and maintain professional accountability
  20. Which FIDO certification level specifically requires security evaluation by an accredited third-party laboratory? Level 2
  21. What is a risk register used for in FIDO Certified Authenticator practice? Tracking identified risks with their status, controls, and owners
  22. Which sampling method is most appropriate when researching FIDO adoption across heterogeneous enterprise sectors? Stratified random sampling by industry sector
  23. What enables compatibility among certified devices? Standardized protocols
  24. A client asks why FIDO2 is more secure than SMS-based OTP. What is the most accurate explanation to provide? FIDO2 uses public-key cryptography so credentials never leave the device
  25. Which CTAP2 command is used by a platform to retrieve a list of credentials stored on an authenticator? authenticatorCredentialManagement
  26. Which body accredits the testing laboratories authorized to perform FIDO security evaluations? The FIDO Alliance directly
  27. Which CTAP2 command would a platform use to enumerate all discoverable credentials stored on an authenticator? authenticatorCredentialManagement with enumerateCredentials
  28. Which FIDO MDS (Metadata Service) data type is used to determine if an authenticator model has been revoked? statusReports containing REVOKED status
  29. Which transport protocol introduced in CTAP2.1 allows authenticators to initiate communication? Hybrid (caBLE)
  30. A relying party wants to accept only hardware security keys, not platform authenticators. Which WebAuthn parameter should it set? authenticatorAttachment: 'cross-platform'
Turn these facts into recall:
Was this helpful?