โ† All POC Flashcard Decks

Security & Access Management Flashcards

7 cards from real POC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security & Access Management flashcards as text
  1. What is the purpose of using `bcrypt` over plain SHA-256 for storing user passwords in Python?

    Answer: bcrypt includes a work factor making it intentionally slow to resist brute-force

    bcrypt's configurable work factor ensures hashing remains computationally expensive even as hardware improves, making large-scale cracking impractical.

  2. When using Python's `subprocess` module, which argument prevents shell injection vulnerabilities?

    Answer: Passing `shell=False` and supplying a list of arguments

    Passing `shell=False` with a list avoids invoking a shell interpreter, so special characters in arguments cannot be interpreted as shell commands.

  3. Which JWT library function in PyJWT verifies both the signature and expiration of a token?

    Answer: jwt.decode()

    `jwt.decode()` verifies the signature using the provided key and automatically checks the `exp` claim if present, raising exceptions on failure.

  4. What Python context manager ensures a file containing sensitive data is automatically deleted after use?

    Answer: tempfile.TemporaryFile()

    `tempfile.TemporaryFile()` automatically deletes the file when the context manager exits, and the file has no persistent filesystem path on most Unix systems.

  5. In Python's `ssl` module, what is the purpose of `ssl.create_default_context()`?

    Answer: Creates a secure context with recommended settings including certificate verification

    `ssl.create_default_context()` returns an `SSLContext` configured with secure defaults: `CERT_REQUIRED`, hostname checking, and the system CA bundle.

  6. Which attack does `secrets.compare_digest()` protect against when validating tokens?

    Answer: Timing attacks

    Constant-time comparison in `secrets.compare_digest()` prevents timing attacks where an attacker infers correct bytes by measuring how long comparisons take.

  7. What is the correct way to prevent SSRF in a Python application that fetches user-supplied URLs?

    Answer: Validate and whitelist allowed hosts/IP ranges before making any outbound request

    Whitelisting allowed hosts ensures the application cannot be tricked into making requests to internal network resources or cloud metadata endpoints.