Courseiva
mediumMultiple Choice

CS0-003 Practice Question: A user receives repeated MFA prompts and…

A user receives repeated MFA prompts and eventually approves one they did not initiate. Which behaviour should the analyst classify this as?

⚠ Common exam trap

The CS0-004 exam often tests the distinction between 'MFA fatigue' and 'password spraying' — candidates mistakenly choose password spraying because they focus on the repeated attempts, but the key is that the attacker already has the password and is abusing the MFA approval process, not guessing passwords.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MFA fatigue or push-bombing attack

Repeated MFA prompts that the user eventually approves out of frustration or habit is the hallmark of MFA fatigue (also called push-bombing). The attacker sends a flood of push notifications to the user's device, hoping the user will mistakenly approve one to stop the annoyance. This bypasses the MFA control without needing to compromise the second factor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Password spraying only

    Why it's wrong here

    Password spraying involves systematically attempting a small set of common passwords against a large number of user accounts to find valid credentials. While it might precede an MFA attack by identifying a working username/password combination, password spraying itself does not generate repeated MFA prompts for a single user. The repeated prompts are a distinct, subsequent phase of an attack designed to exploit the user's authentication mechanism, not the password guessing phase.

  • ✓

    MFA fatigue or push-bombing attack

    Why this is correct

    MFA fatigue, also known as push-bombing, is a social engineering attack where an attacker repeatedly sends multi-factor authentication push notifications to a target user's device after obtaining their primary credentials. The goal is to overwhelm or annoy the user into inadvertently approving one of the prompts, granting the attacker unauthorized access to the account. This tactic exploits human psychology, relying on the user's frustration or distraction to bypass the intended security control.

  • ✗

    DNS tunnelling

    Why it's wrong here

    DNS tunnelling is an exfiltration technique that encodes data within DNS queries and responses to bypass network security controls, often used for command and control or data theft. This method leverages the DNS protocol to create a covert communication channel, effectively smuggling data out of a network. It has no direct relation to generating or responding to multi-factor authentication prompts, which are part of an authentication workflow.

  • ✗

    SSL certificate expiry

    Why it's wrong here

    An expired SSL/TLS certificate indicates that the digital certificate used to establish a secure connection has passed its validity date. This typically results in browser warnings, preventing users from accessing the website securely or at all, as the client cannot verify the server's identity. Certificate expiry is a trust and encryption issue, fundamentally unrelated to generating or approving repeated multi-factor authentication challenges for user login.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.