The point of the example is that with the first choice you have 5% legitimate customers and 5% malicious "customers" and by letting all of them in aka all 10%, you get maximum customer satisfaction including satisfaction of the malicious customers.
Alternatively you reject the malicious customers and as collateral damage accept that some customers do not get their request approved.
You're also confusing "normal operation" with what a user request is. A user request is a request to change something, so by definition it is not the continuation of the existing system. You're thinking that a user request is a HTTP request which is not what's being discussed.
It also is de-facto the case today when logging in as per usual sometimes requires a captcha or additional verification.