FIDO2 and WebAuthn
Standards for public-key sign-in: the W3C Web Authentication API and the FIDO Alliance's CTAP, which let a browser use an authenticator whose key is bound to one website.
FIDO2 is the FIDO Alliance’s set of specifications for sign-in with public-key cryptography, in two parts. Web Authentication (WebAuthn), a W3C standard, is the browser interface a website uses to register and use a credential. The Client to Authenticator Protocol (CTAP) lets the browser or operating system talk to an external authenticator, such as a hardware token; an authenticator built into the device is reached through the operating system instead. At registration the authenticator creates a key pair for that one site and gives the site only the public key. At sign-in the site sends a challenge, and the authenticator signs it with the private key.
The credential is scoped to the site’s domain name, so a signature obtained by a look-alike site is designed to fail at the real one. NIST SP 800-63B-4 section 3.2.5 gives WebAuthn as an example of a standard that provides phishing resistance through this verifier name binding. A passkey is a FIDO credential used this way. FIDO2 underpins much passwordless authentication, and an authenticator unlocked with a PIN or biometric can combine two factors in one step.
Exam relevance: a scenario is likely to ask which method resists phishing, where a FIDO2 security key is expected to rank above a one-time code. Candidates are expected to recognise that a typed code can be relayed while a WebAuthn signature is bound to the real site.