Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium

A network engineer is implementing a REST API security strategy for a new application hosted on a Cisco API Gateway. The goal is to ensure that only authorized clients can access specific API endpoints and that the integrity of the API requests is maintained. The solution must leverage industry-standard tokens for client authentication and authorization. Which security mechanism is most appropriate for authenticating clients accessing the REST API?

  1. ABasic Authentication
  2. BAPI Keys
  3. CMACsec
  4. DOAuth 2.0 with JWTs
Show answer & explanation

Correct answer: D. OAuth 2.0 with JWTs

OAuth 2.0, often used with JSON Web Tokens (JWTs), is an industry-standard framework for delegated authorization that allows clients to access resources on behalf of a user without sharing their credentials. JWTs provide a secure and compact way to transmit information between parties as a JSON object, ensuring both authenticity and integrity, making it ideal for robust API security.

Why the other options are wrong

  • A. Basic Authentication sends credentials in plain text (Base64 encoded) and is generally not recommended for robust API security without SSL/TLS.
  • B. API Keys provide a simple form of authentication but often lack granular authorization capabilities and are less secure than token-based approaches like OAuth 2.0.
  • C. MACsec (802.1AE) provides Layer 2 encryption and integrity for network links, not for authenticating clients accessing a REST API at the application layer.

OAuth 2.0 with JWTs for API Security

An open standard for delegated authorization (OAuth 2.0) often used with JSON Web Tokens (JWTs) to securely grant clients access to protected resources on behalf of a user, providing authentication and authorization for REST APIs.

  • OAuth 2.0 defines roles (resource owner, client, authorization server, resource server) and grant types.
  • JWTs are self-contained, digitally signed tokens containing claims about the user and permissions.
  • JWTs ensure authenticity and integrity through cryptographic signing.
  • Provides a scalable and flexible solution for securing REST APIs.

Memory trick: API Security: Basic, Key, or OAuth Token

More Security questions