← Back to the module

Knowledge check

Passkeys & WebAuthn

10 questions testing what you just read — no login, no tracking, just immediate feedback.

Question 1 of 10

What root cause do a password's three chronic weaknesses (reuse, phishing, breaches) all trace back to?

Question 2 of 10

What does the server store for a registered passkey?

Question 3 of 10

What does the authenticator do during registration to prove it genuinely generated the new key pair?

Question 4 of 10

What identification-scheme pattern does passkey login directly apply?

Question 5 of 10

Why is a fresh challenge on every login important?

Question 6 of 10

What specifically makes passkeys structurally resistant to phishing, unlike passwords or SMS one-time codes?

Question 7 of 10

What's the trade-off of a synced passkey compared to a device-bound one?

Question 8 of 10

In a WebAuthn authenticator data flags byte, what does the User Verified (UV) bit specifically confirm, that User Present (UP) alone does not?

Question 9 of 10

What does the Attested credential data (AT) flag bit indicate when set?

Question 10 of 10

For a WebAuthn flags byte with only User Present (bit 0) and User Verified (bit 2) set, what decimal value results?

0 / 10 answered