Courseiva
hardMultiple Choice

CISM Practice Question: During an incident investigation, the team…

During an incident investigation, the team discovers that an attacker used a valid user's credentials to access a sensitive database. The user's account had multi-factor authentication (MFA) enabled. How is this MOST likely possible?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user approved a fraudulent MFA prompt

MFA fatigue attacks (also known as push bombing) involve an attacker repeatedly sending MFA push notifications to the user until the user, annoyed or confused, approves one. This allows the attacker to bypass MFA without needing the token or password. Option A is less likely because MFA was enabled and properly configured; Option B is incorrect because MFA tokens are generated dynamically and cannot be guessed; Option D is possible but not the most likely given the description that a valid user's credentials were used and MFA was enabled, making user approval the weakest link.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MFA was not properly configured

    Why it's wrong here

    Misconfiguration would typically weaken MFA, yet the stem states MFA was enabled, so the compromise likely came from session-token theft or adversary-in-the-middle phishing that replayed a valid authenticated session. Misconfigured MFA is tempting because weak enrolment or bypass settings genuinely enable credential-only access in poorly deployed tenants.

  • ✗

    The attacker guessed the MFA token

    Why it's wrong here

    Guessing an MFA token is impractical because TOTP codes are short-lived and rate-limited, and the stem gives no sign of brute force. This would fit only if the second factor were a static, guessable value rather than a rotating token.

  • ✓

    The user approved a fraudulent MFA prompt

    Why this is correct

    MFA fatigue attacks flood a user with push notifications until they approve one, granting the attacker a valid authenticated session. Because the credential and second factor were both legitimate, the database access bypassed controls without exploiting any technical vulnerability.

  • ✗

    The attacker used a man-in-the-middle attack

    Why it's wrong here

    A man-in-the-middle attack intercepts traffic but cannot forge the second authentication factor; MFA defeats credential replay unless the session token itself is stolen. MITM is tempting because it genuinely defeats single-factor logins and unencrypted protocols, making it the classic answer when MFA is absent.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.