A developer is implementing OAuth 2.0 for a mobile app (public client) that needs to access a user's data from a third-party API. To mitigate the authorization code interception attack, which OAuth 2.0 extension should be used?
Proof Key for Code Exchange (PKCE) enhances the Authorization Code Grant flow, making it secure for public clients like mobile applications that cannot securely store a client secret. It mitigates the authorization code interception attack by requiring the client to generate a cryptographically random `code_verifier` and a `code_challenge` derived from it. The `code_challenge` is sent with the initial authorization request, and the `code_verifier` is later presented when exchanging the authorization code for an access token, proving the client's identity without a shared secret.
Why this answer
PKCE (Proof Key for Code Exchange) is an extension to OAuth 2.0 designed to mitigate authorization code interception attacks, especially for public clients like mobile apps. It works by having the client generate a code verifier and its transformed code challenge, which are used to bind the authorization request to the token request. This prevents an attacker who intercepts the authorization code from exchanging it for tokens.
Exam trap
CISSP often tests the misconception that the implicit grant is secure for mobile apps, or that PKCE is only for confidential clients, when it is actually critical for public clients.
How to eliminate wrong answers
Option A is wrong because the device code grant is for devices with limited input capabilities, not for mitigating interception. Option B is wrong because the client credentials grant is for machine-to-machine communication without a user context. Option C is wrong because the implicit grant is deprecated and does not provide the same security as PKCE; it returns tokens directly in the URL, which can be intercepted.