Courseiva
Question 937 of 1,013
General Security ConceptshardMultiple ChoiceObjective-mapped

SY0-701 General Security Concepts Practice Question

Exhibit

Phishing awareness results:
Team A: click rate 8%, report rate 6%, median report time 52 min
Team B: click rate 7%, report rate 18%, median report time 14 min
Team C: click rate 12%, report rate 21%, median report time 10 min

Incident summary: Team C had one mailbox takeover after a user approved an MFA push while traveling.

Based on the exhibit, which control would most effectively reduce the remaining successful attacks?

Phishing awareness results: Team A: click rate 8%, report rate 6%, median report time 52 min Team B: click rate 7%, report rate 18%, median report time 14 min Team C: click rate 12%, report rate 21%, median report time 10 min

Incident summary: Team C had one mailbox takeover after a user approved an MFA push while traveling.

⚠ Common exam trap

CompTIA often tests the misconception that any MFA is equally secure; the trap here is that candidates may think push-based MFA is sufficient because it is 'multi-factor,' but the exam expects you to recognize that push-based MFA is vulnerable to fatigue attacks and that phishing-resistant MFA is the appropriate technical control to prevent such successful attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Replace push-based MFA with phishing-resistant MFA and reinforce verification for unusual login prompts.

Team C's successful attack was a mailbox takeover resulting from a user approving an MFA push notification while traveling. This indicates that push-based MFA is vulnerable to MFA fatigue attacks, where an attacker bombards the user with prompts until they approve. Replacing push-based MFA with phishing-resistant MFA (e.g., FIDO2/WebAuthn or hardware tokens) eliminates the possibility of approving a prompt from an untrusted device, and reinforcing verification for unusual login prompts adds a critical user behavior layer to detect anomalies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Continue generic awareness posters without changing technical controls.

    Why it's wrong here

    Generic security awareness posters do not alter the underlying authentication flow that allowed the compromise. In the incident, the user received and approved an MFA push prompt while on an untrusted network, a classic prompt-fatigue attack that no poster can block. Without a technical control such as number matching, location-based conditional access, or replacing push with phishing-resistant credentials, attackers will continue to spam approval requests until a user accepts one. Awareness posters may raise general security knowledge but cannot prevent an attacker from repeatedly sending push prompts to a victim's mobile device.

  • Replace push-based MFA with phishing-resistant MFA and reinforce verification for unusual login prompts.

    Why this is correct

    Replacing push-based MFA with phishing-resistant MFA, such as FIDO2 security keys or passkeys, eliminates the possibility of a remote attacker triggering a simple approval prompt, because the MFA secret is bound to the legitimate service's origin. Reinforcing verification for unusual login prompts—for example, requiring the user to confirm a displayed number or to check the sign-in location—adds a human decision layer that catches prompt fatigue even if a prompt somehow appears. This combination directly counters the reported attack: the travelling employee could not have been phished into approving a push because no push exists, and any abnormal sign-in would trigger an explicit verification step instead of a one-tap 'Yes'.

  • Disable MFA on mobile devices so users can log in faster.

    Why it's wrong here

    Disabling MFA on mobile devices removes the very authentication step that prevented the mailbox takeover in Team C’s incident, where an MFA push approval was the attack vector; the correct control would instead enforce number-matching or location-based conditional access policies in Microsoft Entra ID to block such approvals. This option is tempting because MFA fatigue is a real usability concern, and disabling MFA on mobile devices could reduce friction for travellers, but it would be correct only if the scenario involved excessive login delays causing productivity loss, not a confirmed account compromise.

  • Allow employees to approve prompts from any device to reduce help desk calls.

    Why it's wrong here

    Allowing employees to approve prompts from any device would eliminate the location-based conditional access policy that blocks MFA approvals from untrusted networks, directly enabling the exact attack vector that succeeded against Team C—a user approving a push while travelling. This option is tempting because it reduces friction and help desk calls for legitimate remote access, and would be correct if the goal were to improve user convenience rather than to prevent MFA fatigue attacks.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 30, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.