ETExamTower
Q55Application Deployment and SecurityMultiple answers

Which two countermeasures help to reduce the risk of playback attacks? (Choose two.)

Select 2 answers.
← → navigate · a answer
Community votes
B
50% (3)
E
50% (3)
A
0% (0)
C
0% (0)
D
0% (0)
Discussion · 10
16
I agree with 'B & E'
7
I prefer C & E. HMAC or encryption alone do not give playback protection. You need a timestamp in the data (see JWT). Usually encryption, as in HTTPS instead of HTTP, also handles playback protection.
5
Agree with FR99, B and E. IMO B alone is not going to prevent replay attack, it has to be used together with E. https://en.wikipedia.org/wiki/Replay_attack#General_countermeasure_for_all_replay_attacks
3
B & E will work just fine here. https://aspsecuritykit.net/guides/implementing-hmac-scheme-to-protect-api-requests/
B, E 3
Selected Answer: BE HMAC is one of the most secure ways to authenticate API calls. It has unique properties that protect against MIM attacks like replay and request tampering. ASPSecurityKit provides a complete end-to-end implementation of providers for both server and JS clients to integrate HMAC into your API service. And short-lived tokens.
2
B, C and E all seem reasonable, especially if C has perfect forward secrecy implemented. I do think B & E are the more probable ones.
B, E 2
Selected Answer: BE I agree with B & E
1
C & E also make more sense to me.
1
Poor question, HMAC and encryption don’t provide protection against reply attacks. Timestamps, random session keys, and a password for each transaction do. I would go with end-to-end encryption and short-lived access tokens since e2e is used many times as the proper security mechanism in the DEVCOR Study Guide.
1
HMAC does provide protection against reply attack, so according to me B is the right answer. Additionally, C is not fully correct, as end-to-end encryption might mean symmetric as well as asymmetric (TLS) encryption. In the case of symmetric one, there is no built-in protection against reply attacks, as it gives confidentiality only, not authentication. B & E are the correct ones according to me.