Google
PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #137
A phishing campaign successfully convinces users to grant OAuth permissions to a malicious third-party application. Which control failure MOST likely allowed this?
The correct answer is C. Lack of monitoring and restriction on OAuth consent grants. OAuth abuse bypasses malware controls and depends on identity and consent misconfigurations.
Incident Analysis and Security Control Assessment
Question
A phishing campaign successfully convinces users to grant OAuth permissions to a malicious third-party application. Which control failure MOST likely allowed this?
Options
- AWeak endpoint protection
- BMissing email sandboxing
- CLack of monitoring and restriction on OAuth consent grants
- DMissing antivirus signatures
How the community answered
(66 responses)- A6% (4)
- B14% (9)
- C77% (51)
- D3% (2)
Explanation
OAuth abuse bypasses malware controls and depends on identity and consent misconfigurations.
Topics
#OAuth consent phishing#third-party app risk#identity security controls#control failure analysis
Community Discussion
No community discussion yet for this question.