⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Junior / Associate DevOps [L1] Security Core Fundamentals [L1]

Q: An employee is repeatedly bombarded with MFA push notifications on their phone at 2 AM. Exhausted, they finally click "Approve" just to make it stop. What is this attack?

This is called an MFA Fatigue attack (or MFA Prompt Bombing).

#Security #Security #L1 #DevSecOps #Compliance #IAM
🎙️ Candidate Opening & Architectural Context
""Security in modern DevOps must be automated into the pipeline rather than bolted on after deployment. The interviewer is testing: MFA Fatigue (Prompt Bombing), human-centric security flaws.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Production Solution & Architecture

This is called an MFA Fatigue attack (or MFA Prompt Bombing). Attackers already possess the user's compromised password. They intentionally trigger the application to send dozens or hundreds of MFA push notifications to the user's mobile device, hoping the victim will eventually click "Approve" out of annoyance, fatigue, or by accident. Mitigation: Implement "Number Matching" MFA, where the login screen displays a 2-digit number that the user must physically type into their authenticator app to approve the request, making accidental or fatigue-based approvals impossible.

💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: This is called an MFA Fatigue attack (or MFA Prompt Bombing).."
⚡ 60-Second Elevator Pitch Talking Points
  • Immediate Triage: This is called an MFA Fatigue attack (or MFA Prompt Bombing).
  • Run targeted verification commands before modifying configuration.
  • Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement
Want more Security scenarios?
Explore our complete collection of scenario-based Security interview runbooks.
Browse All Security Questions →

📚 Related Production Scenarios in Security