Courseiva
Security Architecture →hardMultiple Choice

CAS-004 Security Architecture Practice Question

A financial services firm must allow third-party partners to call internal REST APIs. Partners authenticate with their own OAuth 2.0 authorization servers, and the firm must validate tokens without sharing secrets and enforce per-partner rate limits and scopes. Which approach BEST meets these requirements?

⚠ Common exam trap

The trap here is treating network-level trust such as VPN or client certificates as equivalent to token-based authorization with scopes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the API gateway to trust partner-issued JWTs by validating signatures against published JSON Web Key Sets and mapping claims to scopes and rate limits.

Trusting externally issued tokens through published JSON Web Key Sets allows signature verification with public keys, eliminating secret sharing. Claim mapping at the gateway then enforces scopes and per-partner throttling, which is exactly the combination the scenario demands. Symmetric keys, VPN client certificates, and session reissuance each fail at least one stated requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Terminate partner tokens at the gateway and reissue firm-issued session cookies for subsequent API calls.

    Why it's wrong here

    Reissuing session cookies converts a stateless token model into stateful sessions, which complicates horizontal scaling and does not preserve partner scopes. It also requires the gateway to accept and interpret partner tokens anyway, adding complexity without meeting the per-partner rate limiting and scope mapping requirement cleanly.

  • ✓

    Configure the API gateway to trust partner-issued JWTs by validating signatures against published JSON Web Key Sets and mapping claims to scopes and rate limits.

    Why this is correct

    Validating partner-issued JWTs against their published JSON Web Key Sets lets the gateway verify authenticity using public keys, so no shared secret is exchanged. Claims such as issuer, audience, scope, and subject can then drive authorization decisions and per-partner throttling policies at the gateway.

  • ✗

    Require partners to connect through a dedicated VPN and authenticate with client certificates issued by the firm's internal certificate authority.

    Why it's wrong here

    Client certificates and a VPN establish transport identity and network access but do not convey OAuth scopes or per-partner authorization context for API operations. This also forces the firm to issue and manage credentials, contradicting the requirement to avoid secret distribution and to honor partner-issued tokens.

  • ✗

    Issue each partner a shared symmetric key and validate HMAC-signed requests at the API gateway.

    Why it's wrong here

    Shared symmetric keys require distributing and rotating secrets with every partner, and they do not carry scopes or per-partner identity claims natively. This approach also scales poorly and increases blast radius if one key leaks, so it does not satisfy the no-secret-sharing and scope enforcement goals.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.