Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityHard
A company is integrating its custom-built internal applications with a new identity management system using REST APIs. The security team requires a mechanism to ensure that API requests are tamper-proof and that the identity of the client making the request can be verified without needing a direct database lookup for every request. Which security token standard is best suited for this requirement, providing a digitally signed, self-contained token?
- AJWT (JSON Web Token)
- BAPI Key
- CSAML (Security Assertion Markup Language)
- DOAuth 2.0 Access Token
Show answer & explanationAnswer & explanation
Correct answer: A. JWT (JSON Web Token)
JWTs (JSON Web Tokens) are digitally signed, self-contained tokens that can be used to securely transmit information between parties. Because they are signed, their integrity is verifiable, and their self-contained nature means the recipient can verify the identity and claims without immediate database lookups, making them ideal for tamper-proof API authentication where identity verification is key.
Why the other options are wrong
- B. API keys are simple authentication tokens but do not provide tamper-proofing or self-contained identity information that can be verified without a backend lookup.
- C. SAML is an XML-based standard for exchanging authentication and authorization data, primarily used for web browser single sign-on, not typically for REST API request security in this manner.
- D. OAuth 2.0 access tokens are used for delegated authorization, but they are often opaque references to session information on the authorization server, requiring a lookup to verify. JWTs are often used *as* OAuth 2.0 access tokens, but the question specifically asks for the token standard that provides tamper-proofing and self-contained identity.
JSON Web Token (JWT)
A compact, URL-safe means of representing claims to be transferred between two parties. The claims in a JWT are encoded as a JSON object that is digitally signed, providing integrity and authenticity, and making it self-contained.
- Composed of a header, payload, and signature.
- Digitally signed (JWS) for tamper detection and authenticity.
- Self-contained: recipient can verify claims and identity without querying a database.
- Commonly used for API authentication and authorization.
Memory trick: JWTs: Just What's Needed for Signed, Self-Contained API Trust!