What Explains Successful Password Logins Followed by Repeated MFA Failures?
A security analyst reviews domain activity logs and notices the following: Which of the following is the best explanation for what the security analyst has discovered? - 
Community Votes
59% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests advanced log analysis by trapping candidates into choosing malware when they see valid passwords, missing that credential theft plus MFA bypass attempts is a classic modern attack vector.
This question requires interpreting authentication logs that show consistent password success paired with repeated MFA failures. The community consensus confirms this pattern indicates an attacker using compromised credentials while attempting to bypass or brute-force the second factor.
Candidates frequently select Option B (Keylogger) because they associate successful password entries with stolen credentials, failing to recognize that attackers routinely acquire passwords via data breaches and subsequently target MFA through repeated guessing.
Community Discussion (25 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Decoding the Authentication Log Pattern
The scenario presents a critical detail often missed during rushed exam conditions: multiple entries showing successful password authentication followed immediately by failed MFA authentication due to invalid codes. In modern identity frameworks, authentication is sequential. Bypassing the first factor does not grant access; the second factor must also validate successfully.Why Option C is the Best Explanation
Option C correctly identifies an ongoing brute-force attack targeting the account. As noted by top-voted community members, attackers frequently obtain username/password pairs through dark web leaks, phishing, or credential stuffing. Once they possess the password, they proceed to the MFA stage. Since time-based or push-based MFA codes change constantly or require physical device possession, attackers resort to rapid trial-and-error (brute-forcing the MFA token) or suffer repeated rejections. This matches the exact log signature of successful first-factor authentication paired with persistent second-factor failures.Why the Other Options Fall Short
- Option A (Account Locked Out): While repeated failures can trigger lockouts, the logs specifically highlight the pattern of success/failure rather than a terminal lockout state. Lockouts are usually a defensive outcome, not the primary attack explanation.
- Option B (Keylogger Installed): Many candidates choose this, assuming the password was stolen locally. However, as experts clarify, keyloggers explain how the password was obtained, but they do not explain the active, repetitive MFA failures observed in real-time logs. Furthermore, modern attacks rely more on cloud-based credential compromise than endpoint-specific malware for this specific log pattern.
- Option D (Ransomware Deployed): Ransomware manifests as file encryption, lateral movement, and ransom notes—not isolated authentication retry loops. There is zero correlation between the log data and ransomware indicators.
Exam Context & Community Validation
The SY0-701 exam heavily emphasizes understanding attack lifecycles and identity management controls. Community feedback consistently validates that recognizing compromised credentials coupled with MFA circumvention attempts is a core competency. As highlighted in discussions, brute-forcing isn't limited to passwords; it applies to any authentication factor, making C the only technically sound conclusion for active, repetitive guessing behavior.Official Reference
- NIST Special Publication 800-63B: Digital Identity Guidelines
- CompTIA Security+ SY0-701 Objective 2.4: Identify characteristics and content of security reports/logs
- Microsoft Learn: Understand sign-in logs and authentication methods
Exam Strategy
When encountering authentication log questions, analyze the complete multi-step verification process rather than focusing solely on the initial success. If the first factor passes but the second consistently fails, prioritize answers involving compromised credentials and active bypass attempts over assumptions about endpoint malware or passive account states.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →