Skip to content
Tech Interview Prep home
Technical interview guide

Multi-Factor Authentication Design

Combining independent authentication factors, and why some MFA methods are meaningfully stronger than others.

Read
45 min
Practice MCQs
25
Interview QA
25
Edition
v5
Editorial status
Reviewed

Scope: NIST SP 800-63B-4, WebAuthn Level 3, FIDO passkey guidance, TOTP/HOTP, CISA, and OWASP guidance current 2026-09-04.

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Define MFA and evaluate factor independence.

QA-2

Explain why WebAuthn resists real-time phishing proxies.

QA-3

Deploy TOTP safely while stating its limits.

QA-4

Design MFA policy for privileged administrators.

QA-5

Explain biometrics in multi-factor cryptographic authentication.

QA-6

Implement secure WebAuthn credential registration.

QA-7

Validate a WebAuthn authentication assertion.

QA-8

Choose between synced passkeys and device-bound security keys.

QA-9

Design authenticator enrollment, replacement, and removal.

QA-10

Design account recovery that does not nullify MFA.

QA-11

Implement recovery-code issuance and use.

QA-12

Plan lost-device handling for passkey-first accounts.

QA-13

Design risk-adaptive authentication without hidden downgrade.

QA-14

Implement step-up for a high-risk transaction.

QA-15

Protect sessions after successful MFA.

QA-16

Threat-model TOTP seed storage and verification.

QA-17

Diagnose TOTP failures without weakening verification.

QA-18

Harden push-based MFA and plan migration.

QA-19

Design MFA abuse controls and safe errors.

QA-20

Design a helpdesk-assisted MFA reset workflow.

QA-21

Design inclusive MFA enrollment and recovery.

QA-22

Build authenticator and session self-service safely.

QA-23

Respond to an MFA-fatigue campaign.

QA-24

Respond to suspected MFA bypass or authenticator compromise.

QA-25

Define success and safety metrics for an MFA program.