Exercises

Mobile Authentication and Credential Security

Assess your ability to design secure authentication for mobile applications. This quiz covers OAuth 2.0 with PKCE, OpenID Connect, access and refresh tokens, operating-system key stores, verified deep links, TLS validation, certificate pinning, biometric controls, secure logging, token revocation, key rotation, device attestation, and defenses against credential attacks. Questions range from foundational concepts to practical security decisions and architecture analysis.

Answer the questions below and check the explanation for each answer.

0/18 answered

  1. 1

    What is the primary security purpose of PKCE in a mobile OAuth authorization-code flow?

  2. 2

    Where should a mobile app generally store a long-lived refresh token?

  3. 3

    The illustrated TLS chain is missing the intermediate certificate. What is a likely result when the app validates the server?

    Question 3
  4. 4

    In the depicted PKCE flow, what must the mobile app create before opening the authorization page?

    Question 4
  5. 5

    What does biometric authentication usually prove when it unlocks a token stored on a device?

  6. 6

    The image compares a custom-scheme callback with a verified HTTPS callback. What is the main security benefit of the verified HTTPS approach?

    Question 6
  7. 7

    Which validation set is the most appropriate before an API trusts a JWT access token?

  8. 8

    The log excerpt includes an Authorization header. How should production logging handle this field?

    Question 8
  9. 9

    What is the main purpose of a nonce in an OpenID Connect authentication request?

  10. 10

    Why does the illustrated pinning configuration retain a backup public-key pin?

    Question 10
  11. 11

    What should an app and its authorization server do when a user explicitly signs out?

  12. 12

    In the envelope-encryption diagram, what is the role of the key-encryption key?

    Question 12
  13. 13

    Which assumption is safest when designing authentication for devices that may be rooted, jailbroken, or instrumented?

  14. 14

    The chart shows many failed sign-ins across numerous accounts from changing network addresses. Which defense best targets this credential-stuffing pattern?

    Question 14
  15. 15

    Why is an external user-agent, such as the system browser, generally recommended for mobile OAuth authorization?

  16. 16

    A QR-scanning app requests camera, contacts, and continuous location access on first launch. Which security principle is most directly violated?

    Question 16
  17. 17

    How should a backend use a mobile device-attestation result?

  18. 18

    What security benefit does refresh-token rotation with reuse detection provide?

Download the App now to have access to + 5000 free courses, exercises, certificates and lots of content without paying anything!

  • 100% free online courses from start to finish

    Thousands of online courses in video, ebooks and audiobooks.

  • More than 60 thousand free exercises

    To test your knowledge during online courses

  • Valid free Digital Certificate with QR Code

    Generated directly from your cell phone's photo gallery and sent to your email

Cursa app on the ebook screen, the video course screen and the course exercises screen, plus the course completion certificate