mediumMultiple Choice
CS0-003 Practice Question: A user receives repeated MFA prompts and…
A user receives repeated MFA prompts and eventually approves one they did not initiate. Which behaviour should the analyst classify this as?
⚠ Common exam trap
The CS0-004 exam often tests the distinction between 'MFA fatigue' and 'password spraying' — candidates mistakenly choose password spraying because they focus on the repeated attempts, but the key is that the attacker already has the password and is abusing the MFA approval process, not guessing passwords.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MFA fatigue or push-bombing attack
Repeated MFA prompts that the user eventually approves out of frustration or habit is the hallmark of MFA fatigue (also called push-bombing). The attacker sends a flood of push notifications to the user's device, hoping the user will mistakenly approve one to stop the annoyance. This bypasses the MFA control without needing to compromise the second factor.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Password spraying only
Why it's wrong here
Password spraying involves systematically attempting a small set of common passwords against a large number of user accounts to find valid credentials. While it might precede an MFA attack by identifying a working username/password combination, password spraying itself does not generate repeated MFA prompts for a single user. The repeated prompts are a distinct, subsequent phase of an attack designed to exploit the user's authentication mechanism, not the password guessing phase.
- ✓
MFA fatigue or push-bombing attack
Why this is correct
MFA fatigue, also known as push-bombing, is a social engineering attack where an attacker repeatedly sends multi-factor authentication push notifications to a target user's device after obtaining their primary credentials. The goal is to overwhelm or annoy the user into inadvertently approving one of the prompts, granting the attacker unauthorized access to the account. This tactic exploits human psychology, relying on the user's frustration or distraction to bypass the intended security control.
- ✗
DNS tunnelling
Why it's wrong here
DNS tunnelling is an exfiltration technique that encodes data within DNS queries and responses to bypass network security controls, often used for command and control or data theft. This method leverages the DNS protocol to create a covert communication channel, effectively smuggling data out of a network. It has no direct relation to generating or responding to multi-factor authentication prompts, which are part of an authentication workflow.
- ✗
SSL certificate expiry
Why it's wrong here
An expired SSL/TLS certificate indicates that the digital certificate used to establish a secure connection has passed its validity date. This typically results in browser warnings, preventing users from accessing the website securely or at all, as the client cannot verify the server's identity. Certificate expiry is a trust and encryption issue, fundamentally unrelated to generating or approving repeated multi-factor authentication challenges for user login.
Go deeper
Related to this question
Learn chapter
SOC Tier 1, Tier 2, and Tier 3 Analyst Roles
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.