CAS-004 Security Architecture Practice Question
A security architect is evaluating an API security strategy for a SaaS application that supports OAuth 2.0. Which TWO controls should the architect recommend to protect against token interception and replay attacks?
⚠ Common exam trap
CAS-005 often tests the misconception that encrypting a JWT (JWE) prevents replay, when encryption only protects confidentiality — replay protection requires short lifetimes, rotation, or proof-of-possession binding.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforcing short-lived access tokens with refresh token rotation
Option B is correct because enforcing short-lived access tokens limits the window in which a stolen token can be replayed, and refresh token rotation invalidates the old refresh token each time a new one is issued, so a captured refresh token cannot be reused indefinitely. Option D is correct because token binding cryptographically ties an access or refresh token to a specific client session or TLS channel, so a token intercepted and replayed from a different session or connection will be rejected. Option A is wrong because long-lived access tokens increase the replay window and worsen the impact of interception. Option C is wrong because encrypting JWT payloads provides confidentiality of claims but does not prevent an attacker who captures the token from replaying it. Option E is wrong because rate limiting on the token endpoint only mitigates brute-force or flooding attempts; it does not stop interception or replay of a valid token.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using long-lived access tokens to reduce authentication frequency
Why it's wrong here
Long-lived access tokens widen the replay window: a captured bearer token stays valid for hours, so interception yields prolonged unauthorised access. Short-lived tokens with refresh rotation limit that exposure. Long lifetimes suit low-risk internal integrations where re-authentication overhead outweighs interception risk, not an internet-facing SaaS API.
- ✓
Enforcing short-lived access tokens with refresh token rotation
Why this is correct
Short expiry limits the window in which an intercepted token remains usable, directly mitigating replay. Refresh token rotation invalidates the prior refresh token on each exchange, so a stolen refresh token is detected and rejected once the legitimate client rotates, satisfying the replay-resistance requirement.
- ✗
Encrypting JWT payloads with a symmetric key
Why it's wrong here
Encrypting JWT payloads with a symmetric key hides claims from inspection but does not prevent an attacker replaying a captured token; the resource server still accepts it. Encryption suits confidentiality of sensitive claims, such as passing verified attributes through untrusted intermediaries, not replay defence, which needs sender-constrained tokens or nonces.
- ✓
Implementing token binding to bind tokens to a specific client session
Why this is correct
Token binding cryptographically ties the token to the client's TLS session or key pair, so an intercepted token replayed from a different session fails validation. This directly addresses token interception and replay, since possession alone no longer suffices to authenticate.
- ✗
Implementing rate limiting on the token endpoint
Why it's wrong here
Rate limiting the token endpoint throttles credential-stuffing and brute-force attempts against token issuance, but a token intercepted mid-session and replayed to the resource server never touches that endpoint. Rate limiting suits protecting authentication services from volumetric abuse, not replay of already-issued tokens.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.