DevNet Associate (DEVASC) v1.0Application Deployment and SecurityMedium
A web application is designed to handle user authentication and authorization. After a user successfully logs in, the application needs to issue a token that proves the user's identity and their allowed permissions for subsequent requests without re-authenticating. This token should be digitally signed to prevent tampering. Which standard protocol or token type is most appropriate for this scenario?
- ASAML (Security Assertion Markup Language)
- BOAuth 2.0 Access Token
- CAPI Key
- DBasic Authentication
Show answer & explanationAnswer & explanation
Correct answer: B. OAuth 2.0 Access Token
OAuth 2.0 Access Tokens (often implemented as JWTs) are commonly used after authentication to authorize subsequent requests. They carry information about the user's identity and permissions, and can be digitally signed to ensure integrity and prevent tampering.
Why the other options are wrong
- A. SAML is primarily for single sign-on (SSO) and federation, typically exchanging XML assertions, not directly used for per-request authorization tokens in this manner.
- C. API keys are generally for authenticating applications, not individual users, and don't inherently carry user identity or permissions in a signed format.
- D. Basic Authentication sends credentials with every request, which is not efficient for session management and no inherent digital signing for integrity.
OAuth 2.0 Access Token
A credential that represents an authorization granted by the resource owner to the client. It is typically a string (often a JWT) used by the client to make authenticated requests to a protected resource on behalf of the resource owner.
- Issued after successful authentication.
- Authorizes access to protected resources.
- Often a JWT, digitally signed for integrity.
Memory trick: OAuth is for authorization after login, SAML for SSO, Basic for simple creds.