Microsoft Certified: Azure Security Engineer AssociateManage identity and accessEasy
A client organization wants to ensure that all user sign-ins to their Azure AD tenant are protected against replay attacks. They are particularly concerned about tokens being intercepted and reused. Which security feature directly addresses this concern by ensuring that each authentication request is unique and cannot be replayed?
- AAzure AD Identity Protection
- BNonce
- CConditional Access Policies
- DMulti-Factor Authentication (MFA)
Show answer & explanationAnswer & explanation
Correct answer: B. Nonce
A nonce is a cryptographic number used once to prevent replay attacks. It ensures that each authentication request is unique and cannot be intercepted and reused by an attacker.
Why the other options are wrong
- A. Azure AD Identity Protection detects risky sign-ins and users but does not specifically prevent token replay attacks using a unique identifier per request.
- C. Conditional Access Policies control access based on conditions but do not inherently prevent replay attacks on tokens.
- D. MFA adds an extra layer of security but does not directly prevent the replay of an already issued token.
Nonce (Number Used Once)
A nonce is a random, single-use value included in cryptographic communication to prevent replay attacks. It ensures that each message or request is unique and cannot be retransmitted by an attacker.
- Used in authentication protocols like OAuth 2.0 and OpenID Connect.
- Ensures token freshness and prevents re-use.
- Typically generated by the client and validated by the server.
Memory trick: No Old Nonce, New Request, No Replay!