Soru

Zorluk: ZorIncident Response Process and Playbooks

A security operations team responds to an active breach involving a malicious third-party OAuth application that gained consent to access executive mailboxes in a cloud SaaS environment. The application is actively exporting sensitive financial emails via automated API calls. According to standard incident response playbooks for cloud containment, which TWO of the following actions should the team perform immediately? (Select TWO.)

  1. Revoke all active OAuth access and refresh tokens linked to the malicious application.Cevap
  2. Disable the application registration and revoke permissions for its service principal in the identity tenant.Cevap
  3. C
    Initiate full re-imaging of the cloud provider's underlying hypervisor and virtual mail servers.
  4. D
    Purge all historical audit logs and user mailboxes affected by the unauthorized API access.

Cevap

The correct containment steps are revoking active OAuth access and refresh tokens and disabling the application registration with its service principal permissions.
In cloud identity environments, containing malicious third-party OAuth app activity requires severing active API authorizations. Revoking current access and refresh tokens immediately stops ongoing session traffic, while disabling the enterprise application registration and its service principal prevents the attacker from generating fresh tokens or maintaining persistent API access.

Adım Adım Çözüm

1
Identify the vector of active exfiltration
Exfiltration is occurring via API calls using compromised OAuth tokens tied to an authorized application registration.
Containment must target the exact access vector without destroying system evidence or impacting unrelated services.
2
Invalidate existing session tokens
Revoking access and refresh tokens instantly severs current API connections established by the attacker.
Token revocation stops ongoing data transfer in real time during the containment phase.
3
Disable application credentials
Disabling the application registration and its service principal prevents the application from generating new authorization tokens.
This isolates the malicious application within the identity tenant, completing initial containment.

Anahtar Kavram

Cloud SaaS Incident Response and OAuth Application Containment
Tahmini Süre:2m 0s
Bu soruyu puanla