Courseiva
Cloud Application Security →mediumMultiple Choice

CCSP Cloud Application Security Practice Question

A healthcare SaaS provider exposes REST APIs to partner clinics. The security team must ensure that the API cannot be abused by replaying captured requests. The API already uses TLS 1.3 and OAuth 2.0 bearer tokens with short lifetimes. Which additional control best mitigates replay attacks against the API?

⚠ Common exam trap

The trap here is assuming that transport-layer protections like TLS or mTLS automatically prevent application-layer replay of valid requests.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require a unique nonce and timestamp in each request, validated server-side against a replay cache.

Replay attacks occur when a valid request is captured and resent. Defenses must make each request unique and single-use. A server-validated nonce plus timestamp achieves this by rejecting duplicates and expired requests. Transport security such as TLS or mTLS does not stop replay of already-authenticated application requests, and longer token lifetimes worsen exposure. HSTS is browser-focused and irrelevant to server-to-server API replay.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable HTTP Strict Transport Security (HSTS) with a long max-age on the API domain.

    Why it's wrong here

    HSTS forces browsers to use HTTPS, protecting against protocol downgrade and cookie hijacking in browser contexts. It does not prevent an attacker from replaying a captured API request that is already sent over TLS. Partner clinics typically use server-to-server calls where HSTS provides no replay protection.

  • ✗

    Increase the OAuth 2.0 token lifetime to reduce the frequency of token refresh calls.

    Why it's wrong here

    Lengthening token lifetimes increases the window during which a stolen bearer token remains valid, making replay and token theft more damaging rather than less. Shorter lifetimes and token binding are preferable. This change would weaken, not strengthen, resistance to replay attacks in this scenario.

  • ✗

    Enforce mutual TLS between partner clinics and the API gateway.

    Why it's wrong here

    Mutual TLS authenticates both endpoints during the TLS handshake, but it does not prevent an attacker who has captured a valid request from replaying it within the same session or with a still-valid bearer token. The captured HTTP request can be resent over a new TLS connection, so mTLS alone does not address replay of application-layer requests.

  • ✓

    Require a unique nonce and timestamp in each request, validated server-side against a replay cache.

    Why this is correct

    A server-validated nonce combined with a timestamp ensures each request is unique and only accepted once within a defined window. Even if an attacker captures a request, the nonce will already be consumed or the timestamp will be stale, so the server rejects the replay. This directly mitigates replay attacks at the application layer.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.