This describes rate-limiting or lockout policies, which slow down guessing attacks. The second factor is something the attacker is unlikely to have (your phone). This is known as **Multi-factor Authentication** or MFA. A stolen or guessed password is no longer enough on its own. That's the whole point of a second factor!