RESTful API & Middleware Design Flashcards
7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 RESTful API & Middleware Design flashcards as text
In REST API design, which approach correctly models a sub-resource relationship between orders and items?
Answer: /orders/123/items
Nested resource paths like /orders/123/items clearly express hierarchical ownership while keeping URIs resource-oriented.
A middleware component must handle partial outages by shedding load when the system is overloaded. Which pattern implements this?
Answer: Load shedding / bulkhead
The bulkhead pattern isolates failures by limiting concurrent calls to a service, preventing one overloaded component from cascading failures.
What is the key difference between REST and GraphQL in terms of data fetching?
Answer: GraphQL allows clients to specify exactly what data they need in a single query
GraphQL's query language lets clients declare their exact data requirements, eliminating over-fetching and under-fetching common in REST.
Which HTTP header should a REST API use to communicate the rate limit remaining to clients?
Answer: X-Rate-Limit-Remaining or RateLimit-Remaining
X-Rate-Limit-Remaining (or the standardized RateLimit-Remaining per IETF draft) informs clients how many requests they have left in the current window.
When integrating legacy SOAP services with modern REST clients via middleware, which integration approach is most commonly used?
Answer: SOAP-to-REST translation/facade in the API gateway
An API gateway can expose a REST interface while translating requests/responses to SOAP format for the legacy backend, preserving both systems.
In REST API security, what is the primary purpose of using short-lived JWT access tokens alongside refresh tokens?
Answer: To limit the window of exposure if an access token is compromised
Short-lived access tokens minimize damage from token theft, while refresh tokens allow clients to obtain new access tokens without re-authentication.
A system integrator is designing middleware that must guarantee message delivery even if the receiving service is temporarily unavailable. Which pattern ensures this?
Answer: Durable message queuing with persistent storage
Durable message queues persist messages to disk and redeliver them once the consumer is available, guaranteeing at-least-once delivery.