During an API security review, an assessor finds that the API uses JSON Web Tokens (JWT) with a symmetric key shared among multiple services. Which of the following is the MOST significant security concern?
A shared symmetric key means any compromised service can forge valid tokens for every other service, breaking per-service authentication boundaries. Asymmetric signing with per-service keys, or centralised issuance, would contain the blast radius of a single compromised credential.
Why this answer
The most significant security concern is that multiple services share the same symmetric key. With a shared symmetric key, any service can forge tokens that are accepted by other services, leading to a lack of non-repudiation and increased blast radius if one service is compromised. This violates the principle of least privilege and increases the risk of token forgery.
Exam trap
CAS-005 often tests the misconception that encryption is the primary concern for JWTs, but the bigger risk is often key management and sharing, which enables token forgery.
How to eliminate wrong answers
Option A is wrong because while not encrypting the token (using JWS instead of JWE) means the payload is readable, it is not the most significant concern if the token is transmitted over HTTPS and contains no sensitive data; integrity is still protected. Option C is wrong because missing audience claim can lead to token misuse across services, but it is less severe than a shared symmetric key, as the audience claim is a defense-in-depth measure. Option D is wrong because missing expiration increases the window of opportunity for token misuse, but again, it is less critical than a shared key that allows token forgery.