Depending on the strength of defence required, anything from a low-cost registration fee (see Metafilter) to some form of recommendation-and-vetting or simultaneous in-person token-granting event (simultaneous to avoid entities being in two places at once). And auditing for abuse.
There have been several proposals for such systems also assuring some level of anonymity.
It's unlikely any approach will be perfect, though an arbitrary level of assurance is likely possible at some cost.
Note that surreptitiously fingerprinting and preemptively certifying to establish entity uniqueness are vastly different from a user awareness and concent perspective.
Sure, someone can create another account using a new browser, within a VM, from another computer, inside a VPN. It's all about making it much harder. If the primary use of fingerprinting was to protect community from bad actors, like those violating a set of community guidelines, then maybe the extra effort it would take to get around those issues might give them enough time to diffuse.
You could use IP address, although that only works if the user isn't on a public / shared network. It's also easily bypassed by spinning up a VM on a cloud service provider and using an SSH tunnel.
Since you used polls as an example: StrawPoll.me [0] is an online poll site which lets you select different duplication checks based on your requirements. The choices are: IP, browser cookie, none, or require user sign in. They also give you an option to add a CAPTCHA.
* Cookies: Can be deleted * IP-Adress: Not unique, because ISPs rotate them; also VPN * Login: Well create a second one * Methods from Universities using nth letter of name and nth digit of birthdate: Just make up a new name.
Sorry - but unless you are using an analog medium or asking the questions in person the numbers can be inflated and there is no way to have 100% data quality.
But in most contexts this is ok. So I would probably go the most easy way: Cookie.
I would - at least not in the European Union go with fingerprinting and such stuff, as I am not sure how this plays out regarding GDPR as this would be PII you are storing.