CAS-004 Security Architecture Practice Question
A financial services firm must allow third-party partners to call internal REST APIs. Partners authenticate with their own OAuth 2.0 authorization servers, and the firm must validate tokens without sharing secrets and enforce per-partner rate limits and scopes. Which approach BEST meets these requirements?
⚠ Common exam trap
The trap here is treating network-level trust such as VPN or client certificates as equivalent to token-based authorization with scopes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the API gateway to trust partner-issued JWTs by validating signatures against published JSON Web Key Sets and mapping claims to scopes and rate limits.
Trusting externally issued tokens through published JSON Web Key Sets allows signature verification with public keys, eliminating secret sharing. Claim mapping at the gateway then enforces scopes and per-partner throttling, which is exactly the combination the scenario demands. Symmetric keys, VPN client certificates, and session reissuance each fail at least one stated requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Terminate partner tokens at the gateway and reissue firm-issued session cookies for subsequent API calls.
Why it's wrong here
Reissuing session cookies converts a stateless token model into stateful sessions, which complicates horizontal scaling and does not preserve partner scopes. It also requires the gateway to accept and interpret partner tokens anyway, adding complexity without meeting the per-partner rate limiting and scope mapping requirement cleanly.
- ✓
Configure the API gateway to trust partner-issued JWTs by validating signatures against published JSON Web Key Sets and mapping claims to scopes and rate limits.
Why this is correct
Validating partner-issued JWTs against their published JSON Web Key Sets lets the gateway verify authenticity using public keys, so no shared secret is exchanged. Claims such as issuer, audience, scope, and subject can then drive authorization decisions and per-partner throttling policies at the gateway.
- ✗
Require partners to connect through a dedicated VPN and authenticate with client certificates issued by the firm's internal certificate authority.
Why it's wrong here
Client certificates and a VPN establish transport identity and network access but do not convey OAuth scopes or per-partner authorization context for API operations. This also forces the firm to issue and manage credentials, contradicting the requirement to avoid secret distribution and to honor partner-issued tokens.
- ✗
Issue each partner a shared symmetric key and validate HMAC-signed requests at the API gateway.
Why it's wrong here
Shared symmetric keys require distributing and rotating secrets with every partner, and they do not carry scopes or per-partner identity claims natively. This approach also scales poorly and increases blast radius if one key leaks, so it does not satisfy the no-secret-sharing and scope enforcement goals.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.