Security & Access Management Flashcards
7 cards from real POC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security & Access Management flashcards as text
What is the purpose of using `bcrypt` over plain SHA-256 for storing user passwords in Python?
Answer: bcrypt includes a work factor making it intentionally slow to resist brute-force
bcrypt's configurable work factor ensures hashing remains computationally expensive even as hardware improves, making large-scale cracking impractical.
When using Python's `subprocess` module, which argument prevents shell injection vulnerabilities?
Answer: Passing `shell=False` and supplying a list of arguments
Passing `shell=False` with a list avoids invoking a shell interpreter, so special characters in arguments cannot be interpreted as shell commands.
Which JWT library function in PyJWT verifies both the signature and expiration of a token?
Answer: jwt.decode()
`jwt.decode()` verifies the signature using the provided key and automatically checks the `exp` claim if present, raising exceptions on failure.
What Python context manager ensures a file containing sensitive data is automatically deleted after use?
Answer: tempfile.TemporaryFile()
`tempfile.TemporaryFile()` automatically deletes the file when the context manager exits, and the file has no persistent filesystem path on most Unix systems.
In Python's `ssl` module, what is the purpose of `ssl.create_default_context()`?
Answer: Creates a secure context with recommended settings including certificate verification
`ssl.create_default_context()` returns an `SSLContext` configured with secure defaults: `CERT_REQUIRED`, hostname checking, and the system CA bundle.
Which attack does `secrets.compare_digest()` protect against when validating tokens?
Answer: Timing attacks
Constant-time comparison in `secrets.compare_digest()` prevents timing attacks where an attacker infers correct bytes by measuring how long comparisons take.
What is the correct way to prevent SSRF in a Python application that fetches user-supplied URLs?
Answer: Validate and whitelist allowed hosts/IP ranges before making any outbound request
Whitelisting allowed hosts ensures the application cannot be tricked into making requests to internal network resources or cloud metadata endpoints.