โ† All POC Flashcard Decks

Security & Access Management Flashcards

7 cards from real POC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security & Access Management flashcards as text
  1. Which Python library is commonly used to implement OAuth 2.0 flows for authorizing third-party access to resources?

    Answer: requests-oauthlib

    `requests-oauthlib` provides OAuth 1 and OAuth 2 support built on top of the `requests` library, enabling authorization code, client credentials, and other flows.

  2. What Python exception should be caught to handle authentication failures when using `paramiko` for SSH connections?

    Answer: paramiko.AuthenticationException

    `paramiko.AuthenticationException` is raised specifically when SSH credentials (password or key) are rejected by the server.

  3. In Python web applications, what is the purpose of setting the `HttpOnly` flag on session cookies?

    Answer: Prevents JavaScript from accessing the cookie, mitigating XSS cookie theft

    The `HttpOnly` flag instructs the browser to block JavaScript access to the cookie, preventing XSS attacks from stealing session identifiers.

  4. What is the security risk of logging sensitive data such as passwords or tokens using Python's `logging` module?

    Answer: Log files may be accessed by unauthorized users, exposing the sensitive data

    Log files are often stored in plaintext and accessible to system administrators or attackers, making them a common source of credential leakage.

  5. Which `cryptography` library primitive is used to perform RSA public-key encryption in Python?

    Answer: RSAPublicKey with OAEP padding

    RSA encryption uses the public key with OAEP padding via `public_key.encrypt(plaintext, padding.OAEP(...))` from `cryptography.hazmat.primitives.asymmetric`.

  6. What does enabling `SECURE_HSTS_SECONDS` in a Python Django application accomplish?

    Answer: Instructs browsers to only connect via HTTPS for the specified duration via a response header

    Setting `SECURE_HSTS_SECONDS` causes Django to emit the `Strict-Transport-Security` response header, telling browsers to refuse HTTP connections for the configured period.

  7. Which Python standard library module provides the `uuid4()` function for generating cryptographically random identifiers?

    Answer: uuid

    The `uuid` module's `uuid4()` generates a random UUID using `os.urandom()`, making it suitable for generating unpredictable unique identifiers like session IDs.