API Authentication and Security Flashcards
6 cards from real API practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 API Authentication and Security flashcards as text
What is rate limiting in API security?
Answer: Restricting the number of requests a client can make in a time window
Rate limiting restricts the number of API requests a client can make within a specific time window to prevent abuse and DoS attacks.
What does HTTPS provide that HTTP does not?
Answer: Encrypted transmission of data
HTTPS uses TLS/SSL to encrypt data in transit, preventing eavesdropping and man-in-the-middle attacks.
Which OWASP API vulnerability involves an API returning more data than the client needs?
Answer: Excessive Data Exposure
Excessive Data Exposure occurs when an API returns more data than necessary, relying on clients to filter it, exposing sensitive information.
What is CORS in the context of API security?
Answer: A cross-origin resource sharing policy controlling browser requests
CORS (Cross-Origin Resource Sharing) is a browser security policy that controls which origins can make requests to an API.
What is SQL injection in API testing?
Answer: Injecting malicious SQL through API inputs to manipulate the database
SQL injection involves sending malicious SQL code through API parameters to manipulate or access the database unauthorized.
Which grant type in OAuth 2.0 is recommended for server-to-server API communication?
Answer: Client Credentials
The Client Credentials grant type is designed for machine-to-machine communication where no user is involved.