QuestionQ129

Information System Auditing Process

Which item is MOST important to examine when auditing an identity provider’s use of access tokens to govern interaction between an application programming interface (API) and a server?

Explanation

Access-token expiration limits the period in which a bearer token can authorize API access. Enforcing appropriate token lifetimes reduces the exposure window if a token is intercepted, stolen, or leaked.

Community Discussion

No comments yet. Be the first to start the discussion!