DevNet Associate (DEVASC) v1.0Application Deployment and SecurityEasy
A security team is reviewing an application's authentication mechanism. The application uses JWTs (JSON Web Tokens) for session management. Which component of a JWT is used to verify the token's integrity and ensure it hasn't been tampered with?
- APayload
- BSignature
- CHeader
- DExpiration claim
Show answer & explanationAnswer & explanation
Correct answer: B. Signature
The signature part of a JWT is created by hashing the header and payload with a secret key. This signature is then used by the receiver to verify the token's integrity and authenticity.
Why the other options are wrong
- A. The payload contains the claims (data) about the user.
- C. The header specifies the token type and the signing algorithm.
- D. The expiration claim is part of the payload and indicates when the token becomes invalid, not for integrity checking.
JWT Signature
The third part of a JSON Web Token, created by encoding the header and payload and then signing them using a secret key. It's crucial for verifying the token's integrity and authenticity.
- Verifies token integrity.
- Ensures token hasn't been altered.
- Uses a secret key for signing.
Memory trick: Head and Payload tell the story, Signature proves it's true.