MFA requires or more factors to authenticate. Factors fall into categories:
Something you know. Passwords, PINs, security questions.
Something you have. Hardware tokens, phones receiving push notifications or SMS codes, smart cards.
Something you are. Fingerprints, face recognition, other biometrics.
Combining factors defeats credential theft. Stolen passwords don't help without the second factor. FIDO/WebAuthn hardware keys provide phishing-resistant MFA because the key validates the site before responding to authentication challenges.