Concept and mechanism
The number of authentication factors does not alone define phishing resistance. An OTP entered into a fake page can be relayed. Phishing-resistant protocols bind authentication to the legitimate service through specific properties. After a successful attack, existing sessions and issued access mechanisms also need review. In credential stuffing, attackers reuse credential pairs from other breaches. Limiting one IP can be insufficient for distributed attempts. Combine signals, limits, and additional authentication while considering false positives and legitimate-user lockout.
Guided application
Vulnerability priority needs context. Base severity, known exploitation, exposure, criticality, and existing controls are distinct inputs. A higher-rated finding in an isolated lab may not be the first intervention when a critical endpoint faces active exploitation. Keep both situations in the plan and record the reasoning. For dependencies, inventory the artifact actually shipped, including transitive components. A signature helps establish provenance but does not demonstrate absence of vulnerabilities. Handover should identify versions, owners, and how to respond when a dependency needs mitigation or replacement.
Two findings compete for one window: document each asset’s exposure and impact before choosing order. Technical rating is an input, not the entire decision.
Common pitfalls
Treating OTP as automatically phishing-resistant; blocking only one IP; ignoring transitive libraries; sorting only by severity.
Related topics: Application boundaries and secrets · Architecture, privileges, and recovery
Prioritize actual asset risk and retain traceability of assumptions.
Reference: Enterprise patch management planning · SY0-701 V7