Courseiva
Security Architecture →mediumMultiple Choice

CAS-004 Security Architecture Practice Question

A financial services firm is designing a new online banking platform. The security architect must ensure that if the session token issued to a customer is stolen via a cross-site scripting attack, the attacker cannot use it from a different device or network. Which of the following should be implemented to meet this requirement?

⚠ Common exam trap

The trap here is assuming that cookie security flags or shorter lifetimes prevent token replay across devices, when only cryptographic binding to the client's TLS session actually stops cross-device reuse.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Token binding that cryptographically ties the session token to the client's TLS connection.

Token binding is the only mechanism that cryptographically links the session token to the client's TLS connection, so a token stolen via XSS cannot be replayed from a different device or network. Lifetime reduction, cookie flags, and local storage encryption mitigate other risks but do not satisfy the explicit cross-device reuse requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Shortening the session token lifetime to five minutes and requiring re-authentication.

    Why it's wrong here

    A shorter lifetime reduces the window for abuse but does not prevent an attacker who steals the token from using it immediately from another device. The requirement is to stop cross-device reuse entirely, not just limit it, so this control is insufficient on its own.

  • ✓

    Token binding that cryptographically ties the session token to the client's TLS connection.

    Why this is correct

    Token binding uses the TLS layer to cryptographically associate the token with the client's key pair, so a stolen token cannot be replayed from a different TLS connection or device. This directly blocks the cross-device reuse scenario described, even if the token value is exfiltrated through XSS.

  • ✗

    Encrypting the session token with AES-256 before writing it to the client's local storage.

    Why it's wrong here

    Encrypting the token at rest in local storage does not prevent replay if the attacker can read the decrypted value or intercept the token in transit. The binding to the client's TLS session is what stops cross-device reuse, and this option does not provide that binding.

  • ✗

    Storing the session token in an HttpOnly cookie with the Secure and SameSite attributes.

    Why it's wrong here

    HttpOnly, Secure, and SameSite attributes reduce XSS and CSRF exposure but do not bind the token to a specific client. An attacker who obtains the token value through another vector can still replay it from a different device, so the cross-device reuse requirement is unmet.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.