API Authentication & Security Testing Flashcards
6 cards from real API practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 API Authentication & Security Testing flashcards as text
What does JWT stand for in the context of API authentication?
Answer: JSON Web Token
JWT (JSON Web Token) is a compact, URL-safe token format used to securely transmit claims between client and server.
Which part of a JWT contains the user claims and data?
Answer: Payload
The JWT Payload is the middle Base64URL-encoded section that contains the claims, such as user ID, roles, and expiration time.
What is CORS and why is it important in API security testing?
Answer: A browser mechanism controlling cross-origin requests
CORS (Cross-Origin Resource Sharing) is a browser policy that controls which origins can call an API, preventing unauthorized cross-site requests.
Which HTTP status code does an API return when a request lacks valid authentication credentials?
Answer: 401 Unauthorized
401 Unauthorized means the request requires authentication that was not provided or is invalid.
What is a replay attack in the context of API security?
Answer: Sending the same valid request multiple times to exploit the API
A replay attack reuses a captured valid API request (including its token) to perform unauthorized actions.
Which security testing technique sends unexpected or malformed data to an API to discover vulnerabilities?
Answer: Fuzzing
Fuzzing (or fuzz testing) feeds random, invalid, or malformed inputs to an API to uncover crashes, errors, and security flaws.