API Authentication and Security Flashcards
6 cards from real API practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 API Authentication and Security flashcards as text
What does 'Broken Object Level Authorization' (BOLA) mean in API security?
Answer: A user accessing objects they don't own by manipulating IDs
BOLA (also called IDOR) occurs when an API doesn't verify whether a user is authorized to access a specific object, allowing ID manipulation attacks.
Which HTTP response header helps prevent clickjacking attacks on API-served content?
Answer: X-Frame-Options
X-Frame-Options prevents the page from being embedded in iframes, protecting against clickjacking attacks.
What is an API security token expiry time best practice?
Answer: Use short expiry with refresh tokens
Short-lived access tokens combined with refresh tokens reduce the window of opportunity if a token is compromised.
What does 'mass assignment' vulnerability in APIs involve?
Answer: Binding user input directly to internal object properties without filtering
Mass assignment occurs when an API binds client-provided data directly to object properties, allowing attackers to set privileged fields.
Which security practice involves validating that API inputs match expected formats and ranges?
Answer: Input validation
Input validation ensures API inputs conform to expected formats, types, and ranges, preventing injection and other attacks.
What is the purpose of an API gateway in security architecture?
Answer: Centralize authentication, rate limiting, and routing for APIs
An API gateway acts as a single entry point that centralizes security concerns like authentication, authorization, rate limiting, and routing.