RESTful API & Middleware Design Flashcards
7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 RESTful API & Middleware Design flashcards as text
In a microservices architecture, what is the main advantage of using an API gateway over direct service-to-client communication?
Answer: It provides a single entry point for cross-cutting concerns like rate limiting and auth
An API gateway centralizes cross-cutting concerns so individual microservices don't each need to implement them separately.
What distinguishes a 'stateless' REST API interaction from a stateful one?
Answer: Each request contains all information needed for the server to fulfill it without session context
REST statelessness means each request is self-contained; the server maintains no client session state between calls.
Which OAuth 2.0 grant type is most appropriate for a server-to-server REST API integration with no user involvement?
Answer: Client Credentials
Client Credentials grant is designed for machine-to-machine authentication where no user context is required.
A system integrator needs to ensure that duplicate API requests (due to network retries) don't cause duplicate side effects. Which technique addresses this?
Answer: Implementing idempotency keys on non-idempotent endpoints
Idempotency keys allow servers to detect and deduplicate retried requests, returning the original result without re-processing.
In REST API design, what is the correct HTTP method and response code for successfully creating a new resource?
Answer: POST returning 201 Created
POST is used to create resources, and 201 Created with a Location header pointing to the new resource is the standard response.
Which middleware pattern is best suited to aggregate responses from multiple microservice calls into a single API response?
Answer: Backend for Frontend (BFF) pattern
The BFF pattern creates a dedicated backend layer per frontend type that aggregates and tailors data from multiple downstream services.
What is the purpose of the CORS preflight OPTIONS request in REST API communication?
Answer: To ask the server if the actual cross-origin request is permitted
Browsers send a preflight OPTIONS request to verify the server allows the actual cross-origin request's method and headers.