Courseiva
Security Architecture →mediumMultiple Select

CAS-004 Security Architecture Practice Question

A security architect is evaluating an API security strategy for a SaaS application that supports OAuth 2.0. Which TWO controls should the architect recommend to protect against token interception and replay attacks?

⚠ Common exam trap

CAS-005 often tests the misconception that encrypting a JWT (JWE) prevents replay, when encryption only protects confidentiality — replay protection requires short lifetimes, rotation, or proof-of-possession binding.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforcing short-lived access tokens with refresh token rotation

Option B is correct because enforcing short-lived access tokens limits the window in which a stolen token can be replayed, and refresh token rotation invalidates the old refresh token each time a new one is issued, so a captured refresh token cannot be reused indefinitely. Option D is correct because token binding cryptographically ties an access or refresh token to a specific client session or TLS channel, so a token intercepted and replayed from a different session or connection will be rejected. Option A is wrong because long-lived access tokens increase the replay window and worsen the impact of interception. Option C is wrong because encrypting JWT payloads provides confidentiality of claims but does not prevent an attacker who captures the token from replaying it. Option E is wrong because rate limiting on the token endpoint only mitigates brute-force or flooding attempts; it does not stop interception or replay of a valid token.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Using long-lived access tokens to reduce authentication frequency

    Why it's wrong here

    Long-lived access tokens widen the replay window: a captured bearer token stays valid for hours, so interception yields prolonged unauthorised access. Short-lived tokens with refresh rotation limit that exposure. Long lifetimes suit low-risk internal integrations where re-authentication overhead outweighs interception risk, not an internet-facing SaaS API.

  • ✓

    Enforcing short-lived access tokens with refresh token rotation

    Why this is correct

    Short expiry limits the window in which an intercepted token remains usable, directly mitigating replay. Refresh token rotation invalidates the prior refresh token on each exchange, so a stolen refresh token is detected and rejected once the legitimate client rotates, satisfying the replay-resistance requirement.

  • ✗

    Encrypting JWT payloads with a symmetric key

    Why it's wrong here

    Encrypting JWT payloads with a symmetric key hides claims from inspection but does not prevent an attacker replaying a captured token; the resource server still accepts it. Encryption suits confidentiality of sensitive claims, such as passing verified attributes through untrusted intermediaries, not replay defence, which needs sender-constrained tokens or nonces.

  • ✓

    Implementing token binding to bind tokens to a specific client session

    Why this is correct

    Token binding cryptographically ties the token to the client's TLS session or key pair, so an intercepted token replayed from a different session fails validation. This directly addresses token interception and replay, since possession alone no longer suffices to authenticate.

  • ✗

    Implementing rate limiting on the token endpoint

    Why it's wrong here

    Rate limiting the token endpoint throttles credential-stuffing and brute-force attempts against token issuance, but a token intercepted mid-session and replayed to the resource server never touches that endpoint. Rate limiting suits protecting authentication services from volumetric abuse, not replay of already-issued tokens.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.