Courseiva
hardMultiple Choice

CAS-004 API security best practice Practice Question

An organization uses a microservices architecture where services communicate via REST APIs. To ensure defense in depth, they want to authenticate and authorize every API call. Which of the following implementations BEST enforces this at the application layer?

⚠ Common exam trap

For the CompTIA CASP+ exam, the trap is that candidates confuse transport-layer security (mTLS) with application-layer authorization, assuming that mutual authentication alone satisfies the 'authenticate and authorize' requirement, but mTLS provides no mechanism for scoped permissions or user-level claims.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

OAuth 2.0 with JWT bearer tokens and scoped permissions

OAuth 2.0 with JWT bearer tokens and scoped permissions is the best choice because it provides a standardized, token-based authentication and authorization mechanism at the application layer. The JWT contains claims (e.g., issuer, subject, expiration, and scopes) that can be cryptographically verified by each microservice without requiring a centralized session store, enabling fine-grained, per-API authorization. This directly addresses the requirement to authenticate and authorize every API call within a defense-in-depth strategy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Mutual TLS (mTLS) between services

    Why it's wrong here

    Mutual TLS authenticates the service identities at the transport layer, but it does not evaluate user identity, scopes or per-call permissions, so it cannot authorise each API call. mTLS is the correct choice for establishing zero-trust service-to-service channel encryption.

  • ✗

    API keys in HTTP headers

    Why it's wrong here

    API keys identify the calling application but carry no user context, scopes or expiry, so they cannot authorise individual calls per user. They suit simple server-to-server integrations with a single trusted consumer, not defence-in-depth authorisation across microservices.

  • ✓

    OAuth 2.0 with JWT bearer tokens and scoped permissions

    Why this is correct

    OAuth 2.0 with JWT bearer tokens authenticates each API call and enforces authorisation through scoped permissions carried in the token. This satisfies the requirement to authenticate and authorise every REST call at the application layer, providing defence in depth beyond network controls.

  • ✗

    IP whitelisting at the network firewall

    Why it's wrong here

    IP whitelisting operates at the network layer and validates source addresses, not caller identity or permissions, so it cannot authenticate or authorise each REST call. It is the correct control for restricting administrative access to known corporate egress ranges.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CAS-005 exam frequently reuses these exact scenarios with slightly different constraints.

✓OAuth 2.0 with JWT bearer tokens and scoped permissionsCorrect answer▾

Why this is correct

OAuth 2.0 with JWT bearer tokens authenticates each API call and enforces authorisation through scoped permissions carried in the token. This satisfies the requirement to authenticate and authorise every REST call at the application layer, providing defence in depth beyond network controls.

✗Mutual TLS (mTLS) between servicesWrong answer — click to see why▾

Why this is wrong here

mTLS provides transport-layer authentication but does not enforce application-level authorization.

✗API keys in HTTP headersWrong answer — click to see why▾

Why this is wrong here

API keys are static and often lack scoping; they are not as secure or granular as OAuth tokens.

✗IP whitelisting at the network firewallWrong answer — click to see why▾

Why this is wrong here

IP whitelisting is network-level and does not authenticate users or services at the application layer.

Analysis generated from the official CAS-005blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.