One-Time Password (OTP)
A code valid for a single authentication, generated by a token or app from a shared secret and a counter or clock; proves possession of the device but is not phishing-resistant.
A one-time password (OTP) is a code that is accepted only once. A device or app combines a secret shared with the verifier with a changing value. In HOTP (RFC 4226) the changing value is a counter; in TOTP (RFC 6238) it is the current time, so codes expire after a short interval. NIST SP 800-63B-4 treats a single-factor OTP generator, whether a hardware token or an app on a phone, as “something you have”: typing the displayed code proves possession of the authenticator. Because each code is accepted once, a code captured after use has no value in a replay attack.
That single-use property does not stop phishing. A user can be lured to a fake login page and type a valid code, which the attacker relays to the real site at once; SP 800-63B-4 states that OTP authentication is not phishing-resistant. Resisting that relay needs phishing-resistant authentication. A code sent by text message is a different category: SP 800-63B-4 treats it as out-of-band authentication over the telephone network, whose use it restricts, and delivery by text message is also exposed to risks such as SIM swapping.
Exam relevance: a scenario is likely to ask what an OTP protects against. Candidates are expected to credit it with resisting replay and proving possession, and not with stopping a real-time phishing relay.