CAS-004 Security Architecture Practice Question
A financial services firm is designing a new online banking platform. The security architect must ensure that if the session token issued to a customer is stolen via a cross-site scripting attack, the attacker cannot use it from a different device or network. Which of the following should be implemented to meet this requirement?
⚠ Common exam trap
The trap here is assuming that cookie security flags or shorter lifetimes prevent token replay across devices, when only cryptographic binding to the client's TLS session actually stops cross-device reuse.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Token binding that cryptographically ties the session token to the client's TLS connection.
Token binding is the only mechanism that cryptographically links the session token to the client's TLS connection, so a token stolen via XSS cannot be replayed from a different device or network. Lifetime reduction, cookie flags, and local storage encryption mitigate other risks but do not satisfy the explicit cross-device reuse requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Shortening the session token lifetime to five minutes and requiring re-authentication.
Why it's wrong here
A shorter lifetime reduces the window for abuse but does not prevent an attacker who steals the token from using it immediately from another device. The requirement is to stop cross-device reuse entirely, not just limit it, so this control is insufficient on its own.
- ✓
Token binding that cryptographically ties the session token to the client's TLS connection.
Why this is correct
Token binding uses the TLS layer to cryptographically associate the token with the client's key pair, so a stolen token cannot be replayed from a different TLS connection or device. This directly blocks the cross-device reuse scenario described, even if the token value is exfiltrated through XSS.
- ✗
Encrypting the session token with AES-256 before writing it to the client's local storage.
Why it's wrong here
Encrypting the token at rest in local storage does not prevent replay if the attacker can read the decrypted value or intercept the token in transit. The binding to the client's TLS session is what stops cross-device reuse, and this option does not provide that binding.
- ✗
Storing the session token in an HttpOnly cookie with the Secure and SameSite attributes.
Why it's wrong here
HttpOnly, Secure, and SameSite attributes reduce XSS and CSRF exposure but do not bind the token to a specific client. An attacker who obtains the token value through another vector can still replay it from a different device, so the cross-device reuse requirement is unmet.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.