Protecting MFA from Carrier Social Engineering

Answer Correct answer: C — Receiving a push notification to a mobile application protects against carrier social engineering by decoupling authentication from the telephone number.

An organization is concerned about hackers bypassing MFA through social engineering of phone carriers. Which of the following would most likely protect against such an attack?

  1. Receiving alerts about unusual log-in activity
  2. Receiving a six-digit code via SMS
  3. Receiving a push notification to a mobile application Correct Answer
  4. Receiving a phone call for automated approval

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The core concept tested is the vulnerability of SMS-based MFA to carrier interception, with the common trap being the selection of SMS or voice calls which rely on the same telecom infrastructure as the attack vector.

This question addresses how to secure Multi-Factor Authentication (MFA) against SIM-swapping and social engineering attacks targeting phone carriers. It establishes that app-based push notifications are the most effective defense among the given choices.

Candidates often choose B (SMS) because it is the most common form of MFA, failing to recognize that SMS codes can be intercepted via SIM swapping or SS7 exploits, making them vulnerable to the specific threat mentioned.

Community Discussion (5 comments)

shady23 👍 1 Selected: C
Receiving a push notification to a mobile application
salah112 👍 3 Selected: C
C. Receiving a push notification to a mobile application To protect against hackers bypassing Multi-Factor Authentication (MFA) through social engineering of phone carriers, using a push notification to a mobile application is a more secure option. This method is often associated with Time-based One-Time Passwords (TOTP) generated by authenticator apps.
Yomzie 👍 2
Option C: e.g.: Microsoft Authenticator App; Entrust Identity Mobile App.
ganymede 👍 1
C. Receiving a push notification to a mobile application Using an MFA Authenticator App is a better way to go.
Hs1208 👍 1 Selected: C
C. Receiving a push notification to a mobile application( eliminates Social Engineering attack)

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option C is the correct choice because receiving a push notification through a dedicated mobile application (like Microsoft Authenticator or Google Authenticator) does not rely on the telephone network's signaling protocols (SS7) or the physical SIM card. These apps typically use cryptographic challenges or out-of-band data channels over the internet, which prevents attackers who have socially engineered the carrier into transferring the victim's number from authenticating. Since the authentication token is generated and verified within the app environment, the attacker cannot intercept it by simply porting the phone number.

Why the Other Options Are Wrong

Option A (alerts) is a detection mechanism, not a prevention mechanism; it informs the user after a breach attempt but does not stop the hacker from logging in. Option B (SMS) is directly vulnerable to SIM swapping and social engineering of carriers, which is exactly the threat scenario described in the question. Option D (voice call) relies on the same telecommunication infrastructure as SMS and can also be redirected or intercepted if the attacker controls the phone number via the carrier.

Community Comment Notes

The community consensus strongly favors Option C. As salah112 noted, this method "eliminates Social Engineering attack" related to carriers. Yomzie and shady23 also reinforced that authenticator apps are superior for security. Ganymede highlighted that using an MFA Authenticator App is the better approach compared to SMS.

Exam Strategy

When analyzing MFA questions, always look for the phrase 'social engineering of phone carriers' or 'SIM swap'. If these appear, immediately eliminate SMS and Voice options. The correct answer will almost always be an app-based solution (Push notification, TOTP, or Hardware Token) that decouples authentication from the telephone number.

Frequently Asked Questions

Why is SMS not safe against carrier social engineering?

SMS relies on the telecommunications network and the SIM card. Attackers can perform SIM swapping by socially engineering carrier support staff to transfer your number to their device, allowing them to receive your verification codes.

Does a push notification prevent all MFA attacks?

While it prevents carrier-specific attacks like SIM swapping, it is still susceptible to phishing or malware if the device itself is compromised. However, it is significantly more secure than SMS for this specific threat model.

Related Analysis

← Back to SY0-601 Study Guide