ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a security review of a new RESTful service, you notice that once a client's JSON Web Token (JWT) is successfully validated, the gateway caches the authorization decision and allows every subsequent request from that client to bypass token verification for the next 15 minutes. Which security design principle is most directly weakened by this performance optimization?
The principle of complete mediation states that every access to every object must be checked for authorization every single time. Caching an authorization decision for 15 minutes means later requests are not re-validated against the current state of the token or the user's privileges, making the system vulnerable to revoked permissions or stolen tokens. Least privilege concerns the scope of permissions granted, economy of mechanism stresses simplicity of design, and segregation of duties addresses distribution of critical tasks-none of which specifically require re-authorizing each individual request.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the principle of complete mediation?
Open an interactive chat with Bash
How does caching authorization decisions weaken security?
Open an interactive chat with Bash
What is a JSON Web Token (JWT), and how is it used in security?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .