API Authentication & Security Testing Flashcards
6 cards from real API practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 API Authentication & Security Testing flashcards as text
Which authentication mechanism uses a Bearer token included in the Authorization header?
Answer: OAuth 2.0 / JWT
OAuth 2.0 and JWT-based flows pass an access token as a Bearer token in the Authorization header.
What is an API key primarily used for in API security testing?
Answer: Identifying and authenticating the calling application
An API key is a unique identifier passed with requests to authenticate the client application making the call.
Which OWASP API Security risk involves an attacker accessing another user's data by manipulating object IDs?
Answer: Broken Object Level Authorization
Broken Object Level Authorization (BOLA/IDOR) occurs when APIs fail to verify the caller owns the object they are requesting.
What does HTTPS ensure during API communication?
Answer: Encryption of data in transit
HTTPS (HTTP over TLS) encrypts all data exchanged between client and server, preventing eavesdropping and tampering.
Which attack involves sending malicious data in API input fields to manipulate backend database queries?
Answer: SQL Injection
SQL Injection exploits APIs that pass unsanitized user input directly into SQL queries, allowing attackers to read or alter the database.
What is the purpose of rate limiting in API security?
Answer: Prevent abuse by limiting the number of requests per client
Rate limiting restricts how many requests a client can make in a time window, protecting the API from brute force and DoS attacks.