Which control most effectively mitigates a man-in-the-middle attack against a REST API?
Choose an answer
Tap an option to check your answer.
Correct answer: SSL certificates.
Why this is the answer
SSL certificates (and the underlying TLS protocol) provide encryption for data in transit and server authentication. This prevents a man-in-the-middle attacker from intercepting and reading sensitive API requests/responses or impersonating the legitimate API server. Password hashes protect stored passwords, not data in transit. Nonrepudiation ensures a sender cannot deny sending a message, but doesn't prevent interception or impersonation. Biometric authentication verifies user identity at the client, not the integrity or confidentiality of the API communication channel.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed