mediumMultiple ChoiceObjective-mapped
CS0-003 Practice Question: Approving an unexpected OAuth consent prompt for…
A user reports approving an unexpected OAuth consent prompt for an app named 'Invoice Reader'. The app now has mailbox read permissions. What should the incident responder do first? During detection and analysis, which decision is most defensible?
⚠ Common exam trap
CompTIA often tests the misconception that password resets or MFA can mitigate OAuth consent attacks, when in reality the OAuth grant is independent of the user's authentication credentials and must be explicitly revoked.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Revoke the app grant, review mailbox access, and identify other users who consented
The incident responder must first revoke the malicious OAuth app grant to immediately stop the attacker's access via the delegated mailbox permissions. Following revocation, reviewing mailbox access logs (e.g., Mailbox Audit Log, EWS/Graph API calls) is essential to assess the scope of compromise, and identifying other users who consented to the same app is critical to contain lateral movement. This aligns with the NIST SP 800-61 incident response lifecycle's containment and eradication phase.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ignore it if MFA is enabled
Why it's wrong here
MFA does not stop an already granted OAuth app permission.
- ✗
Delete all emails from the mailbox
Why it's wrong here
Deleting mail destroys evidence and may not remove access.
- ✗
Only reset the user's Windows password
Why it's wrong here
Password reset alone does not remove the malicious app consent.
- ✓
Revoke the app grant, review mailbox access, and identify other users who consented
Why this is correct
OAuth consent abuse can persist without password access; revoking grants and scoping exposure contains the incident. In detection and analysis, responders need action that reduces risk while preserving the investigation record.
Go deeper
Related to this question
Learn chapter
SIEM Log Analysis
Key term
Eradication
Eradication is the phase in incident response where the root cause of a security breach is completely removed from the system to prevent the attack from happening again.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.