nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #137

A phishing campaign successfully convinces users to grant OAuth permissions to a malicious third-party application. Which control failure MOST likely allowed this?

The correct answer is C. Lack of monitoring and restriction on OAuth consent grants. OAuth abuse bypasses malware controls and depends on identity and consent misconfigurations.

Incident Analysis and Security Control Assessment

Question

A phishing campaign successfully convinces users to grant OAuth permissions to a malicious third-party application. Which control failure MOST likely allowed this?

Options

  • AWeak endpoint protection
  • BMissing email sandboxing
  • CLack of monitoring and restriction on OAuth consent grants
  • DMissing antivirus signatures

How the community answered

(66 responses)
  • A
    6% (4)
  • B
    14% (9)
  • C
    77% (51)
  • D
    3% (2)

Explanation

OAuth abuse bypasses malware controls and depends on identity and consent misconfigurations.

Topics

#OAuth consent phishing#third-party app risk#identity security controls#control failure analysis

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice