Quiz 10 Question 7 of 20

An analyst sees an attacker replaying a stolen SaaS OAuth token to list storage buckets via API, with no OS process or password logon. Which ATT&CK technique category should guide the mapping?

Select an answer to reveal the explanation.

Motivation