ISC Identity And Access Management Architecture Practice Question
Which TWO methods are used to prevent 'Token Replay' attacks in an OAuth/OIDC architecture?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use of a 'nonce' in the OIDC request.
DPoP and nonces are both techniques used to bind tokens to the specific request session, preventing replay.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Storing tokens in client-side cookies.
Why it's wrong here
Cookies are susceptible to CSRF/theft.
- ✓
Use of a 'nonce' in the OIDC request.
Why this is correct
Links the response token to the request.
- ✓
DPoP (Demonstrating Proof-of-Possession).
Why this is correct
Cryptographically binds tokens to the client.
- ✗
Disabling all token refresh capabilities.
Why it's wrong here
This hurts usability and does not prevent replay.
- ✗
Using long-lived access tokens.
Why it's wrong here
Long-lived tokens increase the risk of replay.
About these practice questions
This ISC question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official (ISC)² exam blueprint
This ISC practice question is part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ISC exam.