shieldCISSP Practice Domain 5 — Identity and Access Management (IAM) Q83 of 120

Which OAuth 2.0 flow is RECOMMENDED for SPAs and mobile apps in 2024?

A CISSP practice question covering Domain 5: Identity and Access Management (IAM). Try answering before reading the explanation below.

Show options & answer
A
Implicit grant
B
Authorization Code with PKCE
✓ Correct answer
C
Resource Owner Password Credentials
D
Client Credentials
Why "Authorization Code with PKCE" is the right answer

Authorization Code + PKCE replaced Implicit grant as the recommended public-client flow. Implicit is deprecated. ROPC is anti-pattern (apps shouldn't see passwords). Client Credentials is for server-to-server.

Study videos for this topic

Want to go deeper on Domain 5? Watch the full breakdown — every video is free, no account, no upsell.

Take the full CISSP practice test
120 questions, instant explanations, study-video links on every miss. No account.
Start full test →