Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityHard

A security architect is evaluating a cloud provider's API security. The provider uses OAuth 2.0 for authorization. The architect notes that client applications are granted access tokens directly after user authentication without an authorization server mediating the process. Which OAuth 2.0 flow is being improperly used or misinterpreted, leading to a potential security vulnerability?

  1. AImplicit Grant (Deprecated)
  2. BResource Owner Password Credentials Grant (Deprecated)
  3. CClient Credentials Grant
  4. DAuthorization Code Grant
Show answer & explanation

Correct answer: A. Implicit Grant (Deprecated)

The scenario describes the Implicit Grant flow, where the access token is returned directly to the client after authentication, often through a browser redirect. This flow is deprecated due to security risks like token leakage via browser history or referrer headers, precisely because it bypasses the authorization server for direct token issuance.

Why the other options are wrong

  • B. Resource Owner Password Credentials Grant involves the client directly handling the user's credentials, which is highly insecure and also deprecated; the scenario implies the user authenticates directly with the provider, not via the client.
  • C. Client Credentials Grant is for machine-to-machine communication, where the client authenticates itself to get a token, not involving a user authentication step as described.
  • D. Authorization Code Grant is the recommended secure flow, where the client receives an authorization code first, which is then exchanged securely with the authorization server for an access token.

OAuth 2.0 Implicit Grant

An OAuth 2.0 authorization flow where the access token is issued directly to the client (typically a browser-based application) by the authorization server, often via a URL fragment, without an intervening authorization code exchange.

  • Deprecated due to security vulnerabilities (e.g., token leakage).
  • Access token is exposed in the browser's URL.
  • Replaced by Authorization Code Flow with PKCE for public clients.

Memory trick: OAuth grants: codes are safe, direct tokens are risky.

More Cloud Security questions