Protecting MFA from Carrier Social Engineering
An organization is concerned about hackers bypassing MFA through social engineering of phone carriers. Which of the following would most likely protect against such an attack?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The core concept tested is the vulnerability of SMS-based MFA to carrier interception, with the common trap being the selection of SMS or voice calls which rely on the same telecom infrastructure as the attack vector.
This question addresses how to secure Multi-Factor Authentication (MFA) against SIM-swapping and social engineering attacks targeting phone carriers. It establishes that app-based push notifications are the most effective defense among the given choices.
Candidates often choose B (SMS) because it is the most common form of MFA, failing to recognize that SMS codes can be intercepted via SIM swapping or SS7 exploits, making them vulnerable to the specific threat mentioned.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option C is the correct choice because receiving a push notification through a dedicated mobile application (like Microsoft Authenticator or Google Authenticator) does not rely on the telephone network's signaling protocols (SS7) or the physical SIM card. These apps typically use cryptographic challenges or out-of-band data channels over the internet, which prevents attackers who have socially engineered the carrier into transferring the victim's number from authenticating. Since the authentication token is generated and verified within the app environment, the attacker cannot intercept it by simply porting the phone number.Why the Other Options Are Wrong
Option A (alerts) is a detection mechanism, not a prevention mechanism; it informs the user after a breach attempt but does not stop the hacker from logging in. Option B (SMS) is directly vulnerable to SIM swapping and social engineering of carriers, which is exactly the threat scenario described in the question. Option D (voice call) relies on the same telecommunication infrastructure as SMS and can also be redirected or intercepted if the attacker controls the phone number via the carrier.Community Comment Notes
The community consensus strongly favors Option C. As salah112 noted, this method "eliminates Social Engineering attack" related to carriers. Yomzie and shady23 also reinforced that authenticator apps are superior for security. Ganymede highlighted that using an MFA Authenticator App is the better approach compared to SMS.Exam Strategy
When analyzing MFA questions, always look for the phrase 'social engineering of phone carriers' or 'SIM swap'. If these appear, immediately eliminate SMS and Voice options. The correct answer will almost always be an app-based solution (Push notification, TOTP, or Hardware Token) that decouples authentication from the telephone number.
Frequently Asked Questions
Why is SMS not safe against carrier social engineering?
SMS relies on the telecommunications network and the SIM card. Attackers can perform SIM swapping by socially engineering carrier support staff to transfer your number to their device, allowing them to receive your verification codes.
Does a push notification prevent all MFA attacks?
While it prevents carrier-specific attacks like SIM swapping, it is still susceptible to phishing or malware if the device itself is compromised. However, it is significantly more secure than SMS for this specific threat model.