API Testing Certification Exam — Questions and Answers
Question 1: What is a 'soak test' (endurance test) in API performance testing?
- A test that runs at normal load for an extended period to detect memory leaks (Correct answer)
- A test with extremely high traffic spikes
- A test that checks API responses for correctness
- A test with zero load to measure baseline
Correct answer: A test that runs at normal load for an extended period to detect memory leaks
Soak testing (endurance testing) runs the API at sustained normal load for hours or days to detect degradation, memory leaks, and resource exhaustion.
Question 2: What is 'contract testing' in API testing?
- Running tests against endpoints explicitly listed in the API service contract document
- Verifying that an API provider and its consumers agree on the expected structure and behavior of the API interface (Correct answer)
- Automatically generating service level agreements from API test result data
- Verifying that API usage agreements between companies are legally enforceable
Correct answer: Verifying that an API provider and its consumers agree on the expected structure and behavior of the API interface
Contract testing verifies that both the API provider and its consumers honor a shared contract defining the expected request/response format, ensuring compatibility without full end-to-end integration tests.
Question 3: What format do SOAP API messages use for their payload?
- CSV
- JSON
- XML (Correct answer)
- YAML
Correct answer: XML
SOAP messages are always XML-formatted, wrapped in an Envelope element containing optional Header and mandatory Body elements.
Question 4: Which HTTP response header helps prevent clickjacking attacks on API-served content?
- X-Frame-Options (Correct answer)
- Accept-Encoding
- Content-Type
- Cache-Control
Correct answer: X-Frame-Options
X-Frame-Options prevents the page from being embedded in iframes, protecting against clickjacking attacks.
Question 5: Which Postman variables enable data access across collections, requests, test scripts, and environments?
- Environment variables
- Local variables
- Global variables (Correct answer)
- Collection variables
Correct answer: Global variables
Global variables in Postman have the broadest scope, meaning they can be accessed by any request, collection, or environment within your Postman workspace. This makes them ideal for storing data that needs to be shared across multiple tests or workflows, such as authentication tokens or base URLs that might change infrequently. Their wide accessibility ensures data consistency across your testing efforts.
Question 6: What is a GraphQL 'fragment' used for in testing and development?
- Reusing a set of fields across multiple queries to reduce duplication (Correct answer)
- Fragmenting requests for performance
- Partial schema definitions
- Breaking a large API into smaller parts
Correct answer: Reusing a set of fields across multiple queries to reduce duplication
GraphQL fragments define reusable sets of fields that can be included in multiple queries, reducing repetition and keeping test queries DRY.
Question 7: What is a GraphQL 'subscription' used for?
- Receiving real-time data push updates from the server over WebSocket (Correct answer)
- Subscribing to API changelog notifications
- Defining optional query fields
- Paying for GraphQL API access
Correct answer: Receiving real-time data push updates from the server over WebSocket
GraphQL subscriptions use WebSocket connections to push real-time updates from the server to the client when data changes occur.
Question 8: What is the goal of load testing an API?
- Validate JSON schema
- Find security vulnerabilities
- Evaluate API behavior under expected peak traffic (Correct answer)
- Test authentication flows
Correct answer: Evaluate API behavior under expected peak traffic
Load testing simulates expected production traffic levels to ensure the API meets performance requirements under real-world conditions.
Question 9: What does 'throughput' measure in API performance testing?
- Memory usage on the server
- Error rate percentage
- Number of requests processed per unit of time (Correct answer)
- Average response size
Correct answer: Number of requests processed per unit of time
Throughput measures how many API requests a system can successfully handle per second or minute, indicating capacity.
Question 10: What does the Retry-After header tell an API client?
- The time the request was received
- The server's uptime
- When the API was last updated
- How long to wait before making another request after a rate limit or 503 (Correct answer)
Correct answer: How long to wait before making another request after a rate limit or 503
The Retry-After header tells the client how many seconds to wait before retrying, used with 429 Too Many Requests and 503 responses.
Question 11: What is the recommended structure for API error response bodies?
- Plain text description
- A structured object with error code, message, and details (Correct answer)
- An empty body
- Just an HTTP status code
Correct answer: A structured object with error code, message, and details
Best practice error responses include a structured object with a machine-readable error code, human-readable message, and optional details for debugging.
Question 12: What is an 'idempotency key' used for in API design?
- Caching responses
- Allowing clients to safely retry requests without duplicate side effects (Correct answer)
- Identifying the API version
- Encrypting requests
Correct answer: Allowing clients to safely retry requests without duplicate side effects
An idempotency key is a unique client-provided identifier that allows servers to recognize and safely ignore duplicate retried requests.
Question 13: What is pagination in REST API design used for?
- Counting API pages
- Caching query results
- Dividing large result sets into smaller, manageable pages (Correct answer)
- Versioning API documentation
Correct answer: Dividing large result sets into smaller, manageable pages
Pagination splits large collections into pages, reducing response size, improving performance, and preventing overloading clients and servers.
Question 14: What is the primary HTTP method used to send GraphQL queries and mutations?
- POST (Correct answer)
- DELETE
- GET
- PUT
Correct answer: POST
GraphQL typically uses HTTP POST with a JSON body containing the query string, variables, and operation name.
Question 15: What is 'logging' in API error debugging and why is it important?
- Storing API credentials
- Archiving old API versions
- Recording request/response details and errors to trace and diagnose issues (Correct answer)
- Writing API documentation
Correct answer: Recording request/response details and errors to trace and diagnose issues
API logging records requests, responses, errors, and context details, enabling developers to trace issues, diagnose bugs, and monitor health in production.
Question 16: What is hypermedia in the context of REST API responses?
- Links embedded in responses that guide clients to related resources and actions (Correct answer)
- Compressed API responses
- HTML media types
- High-bandwidth media files
Correct answer: Links embedded in responses that guide clients to related resources and actions
Hypermedia in REST responses means including links (URLs) to related resources and allowed actions, enabling self-documenting, navigable APIs.
Question 17: What is the GraphQL introspection query used for?
- Authenticate with the GraphQL server
- Query the schema to discover available types, fields, and operations (Correct answer)
- Monitor GraphQL performance
- Test GraphQL mutations
Correct answer: Query the schema to discover available types, fields, and operations
Introspection allows clients to query the GraphQL server's own schema meta-information, enabling tools to auto-generate documentation and queries.
Question 18: What HTTP status code indicates a resource was successfully created?
- 200 OK
- 201 Created (Correct answer)
- 202 Accepted
- 204 No Content
Correct answer: 201 Created
201 Created is the standard response when a POST request successfully creates a new resource.
Question 19: Which HTTP status code does an API return when a request lacks valid authentication credentials?
- 404 Not Found
- 400 Bad Request
- 401 Unauthorized (Correct answer)
- 403 Forbidden
Correct answer: 401 Unauthorized
401 Unauthorized means the request requires authentication that was not provided or is invalid.
Question 20: Which modern performance testing tool uses JavaScript-based scripts and is popular for CI/CD integration?
- k6 (Correct answer)
- Gatling
- LoadRunner
- JMeter
Correct answer: k6
k6 by Grafana Labs uses JavaScript test scripts and is designed for developer-friendly, CI/CD-integrated performance testing.
Question 21: What is a 400 Bad Request status code used for?
- Resource not found
- The client sent a malformed or invalid request (Correct answer)
- Server failure
- Authentication failure
Correct answer: The client sent a malformed or invalid request
400 Bad Request indicates the server cannot process the request due to client-side errors like invalid syntax, missing parameters, or malformed JSON.
Question 22: What is OpenAPI Specification (OAS)?
- A standard format for describing REST API structure and behavior (Correct answer)
- A server infrastructure standard
- A programming language for APIs
- An API testing framework
Correct answer: A standard format for describing REST API structure and behavior
OpenAPI Specification is a standard, language-agnostic format for describing REST APIs, enabling automated tooling for documentation and testing.
Question 23: What is SQL injection in API testing?
- Inserting valid SQL into the database
- Optimizing SQL queries in API calls
- A method for seeding test data
- Injecting malicious SQL through API inputs to manipulate the database (Correct answer)
Correct answer: Injecting malicious SQL through API inputs to manipulate the database
SQL injection involves sending malicious SQL code through API parameters to manipulate or access the database unauthorized.
Question 24: Which OpenAPI component is used to define reusable request/response schemas across multiple endpoints?
- components/schemas (Correct answer)
- servers
- paths
- info
Correct answer: components/schemas
The 'components/schemas' section defines reusable schema objects that can be referenced via $ref throughout the OpenAPI spec.
Question 25: Which authentication mechanism uses a Bearer token included in the Authorization header?
- OAuth 2.0 / JWT (Correct answer)
- Basic Auth
- Digest Auth
- API Key in URL
Correct answer: OAuth 2.0 / JWT
OAuth 2.0 and JWT-based flows pass an access token as a Bearer token in the Authorization header.
Question 26: Which part of a JWT contains the user claims and data?
- Header
- Algorithm
- Signature
- Payload (Correct answer)
Correct answer: Payload
The JWT Payload is the middle Base64URL-encoded section that contains the claims, such as user ID, roles, and expiration time.
Question 27: What does WS-Security provide in SOAP web service testing?
- SOAP rate limiting
- A standardized way to apply security measures like encryption and digital signatures to SOAP messages (Correct answer)
- WSDL file encryption
- Faster SOAP message delivery
Correct answer: A standardized way to apply security measures like encryption and digital signatures to SOAP messages
WS-Security is a SOAP extension standard that enables message-level security including authentication tokens, XML encryption, and digital signatures.
Question 28: Which HTTP header indicates what response media types the client can accept?
- Accept (Correct answer)
- Content-Type
- Authorization
- X-Request-ID
Correct answer: Accept
The Accept header tells the server which content types the client can process in the response.
Question 29: Which grant type in OAuth 2.0 is recommended for server-to-server API communication?
- Client Credentials (Correct answer)
- Password
- Implicit
- Authorization Code
Correct answer: Client Credentials
The Client Credentials grant type is designed for machine-to-machine communication where no user is involved.
Question 30: What does 'changelog' maintenance mean in the context of API documentation best practices?
- Documenting every breaking and non-breaking change between API versions (Correct answer)
- Auditing who accesses the API
- Tracking server performance changes
- Logging all API requests
Correct answer: Documenting every breaking and non-breaking change between API versions
An API changelog records what changed between versions — new endpoints, deprecated fields, breaking changes — helping consumers know what to update.
Question 31: Which Postman feature enables you to simulate an API server and return predefined responses without a real backend?
- Postman Collection Runner
- Postman Monitor
- Postman Interceptor
- Postman Mock Server (Correct answer)
Correct answer: Postman Mock Server
Postman Mock Servers use saved response examples within a collection to create a hosted simulated API that returns predefined responses to incoming requests.
Question 32: Which tool is commonly used for API security scanning and vulnerability detection?
- Selenium
- Swagger Editor
- Grafana
- OWASP ZAP (Correct answer)
Correct answer: OWASP ZAP
OWASP ZAP (Zed Attack Proxy) is an open-source security scanner that can intercept, analyze, and attack API endpoints to find vulnerabilities.
Question 33: What is the difference between latency and response time in API performance testing?
- Response time is measured at the server; latency at the client
- Latency is network delay; response time includes processing and latency (Correct answer)
- Latency measures payload size; response time measures speed
- They are identical metrics
Correct answer: Latency is network delay; response time includes processing and latency
Latency refers to the network travel time, while response time is the total duration from request send to response receipt, including server processing.
Question 34: What does JWT stand for?
- Java Web Token
- JSON Web Token (Correct answer)
- JavaScript Widget Token
- Joint Web Transfer
Correct answer: JSON Web Token
JWT stands for JSON Web Token, a compact, URL-safe token format used for securely transmitting information between parties.
Question 35: What does CRUD stand for in API testing context?
- Connect, Request, Update, Delete
- Configure, Run, Understand, Deploy
- Create, Request, Undo, Debug
- Create, Read, Update, Delete (Correct answer)
Correct answer: Create, Read, Update, Delete
CRUD stands for Create, Read, Update, Delete — the four fundamental operations for persistent storage.
Question 36: Which tool uses an OpenAPI or API Blueprint spec to run contract tests against a live API?
- OWASP ZAP
- Locust
- k6
- Dredd (Correct answer)
Correct answer: Dredd
Dredd is an open-source HTTP API testing framework that validates a live API against its OpenAPI or API Blueprint specification document.
Question 37: What does 'request matching' mean in the context of API mock servers?
- Comparing two separate API requests to detect differences in their structure
- Validating that all request headers conform to the API's published specification
- The process by which a mock server evaluates incoming request attributes to determine which configured response to return (Correct answer)
- Confirming that HTTP methods used by client and server are syntactically identical
Correct answer: The process by which a mock server evaluates incoming request attributes to determine which configured response to return
Request matching is how mock servers evaluate attributes of an incoming request—such as URL, method, headers, and body—against configured rules to select the appropriate canned response.
Question 38: What is the benefit of using test tags or categories in an API automation suite?
- Generate API documentation
- Improve API response time
- Measure test coverage automatically
- Selectively run subsets of tests based on criteria like smoke, regression, or security (Correct answer)
Correct answer: Selectively run subsets of tests based on criteria like smoke, regression, or security
Tags allow teams to selectively execute specific test groups, such as running only smoke tests after a deployment or full regression tests nightly.
Question 39: Which assertion type verifies that an API response matches a predefined JSON structure?
- Response time assertion
- Schema validation assertion (Correct answer)
- Header assertion
- Status code assertion
Correct answer: Schema validation assertion
Schema validation assertions verify the response body conforms to a defined JSON Schema, ensuring correct field names, types, and required properties.
Question 40: When should you prefer integration testing against real APIs over mock-based testing?
- During final acceptance testing when verifying actual compatibility with the real third-party service is critical (Correct answer)
- When network connectivity to the real API is slow or unreliable during development
- When the development environment has insufficient resources to maintain real API connections
- Whenever you want faster test feedback cycles in the local development environment
Correct answer: During final acceptance testing when verifying actual compatibility with the real third-party service is critical
Real API integration tests are essential during acceptance testing to validate that your code works correctly with the actual service, even though mocks are preferred for most unit and integration tests.
Question 41: What is 'fault injection testing' for APIs?
- Injecting test data into the API
- Testing with corrupted hardware
- Deliberately introducing failures to verify the system's resilience and error handling (Correct answer)
- SQL injection security testing
Correct answer: Deliberately introducing failures to verify the system's resilience and error handling
Fault injection testing deliberately introduces failures (network delays, errors, timeouts) to verify the API system handles them gracefully.
Question 42: What is CORS in the context of API security?
- A token format
- A caching mechanism
- An encryption standard
- A cross-origin resource sharing policy controlling browser requests (Correct answer)
Correct answer: A cross-origin resource sharing policy controlling browser requests
CORS (Cross-Origin Resource Sharing) is a browser security policy that controls which origins can make requests to an API.
Question 43: What is 'boundary value testing' in API test design?
- Testing at the minimum and maximum allowed input values (Correct answer)
- Testing API network boundaries
- Testing rate limit boundaries only
- Testing cross-region APIs
Correct answer: Testing at the minimum and maximum allowed input values
Boundary value testing checks API behavior at the edges of valid input ranges — at minimum, maximum, just below minimum, and just above maximum values.
Question 44: What does a 429 Too Many Requests response indicate?
- Database query limit reached
- The client has exceeded the API rate limit (Correct answer)
- Too many parameters in the request
- Server memory limit hit
Correct answer: The client has exceeded the API rate limit
429 Too Many Requests is returned when a client has sent more requests than allowed by the rate limiting policy within a time window.
Question 45: What is 'query depth limiting' used for in GraphQL security testing?
- Restricting query response size
- Limiting the number of fields per query
- Setting timeout thresholds for queries
- Preventing deeply nested queries that could cause excessive database load or DoS (Correct answer)
Correct answer: Preventing deeply nested queries that could cause excessive database load or DoS
Query depth limiting rejects GraphQL queries that exceed a maximum nesting depth, preventing attackers from crafting expensive recursive queries.
Question 46: What is 'cursor-based pagination' in APIs?
- Sorting results alphabetically
- Using an opaque pointer to the next result set instead of page numbers (Correct answer)
- Caching partial responses
- Using mouse position to page results
Correct answer: Using an opaque pointer to the next result set instead of page numbers
Cursor-based pagination uses an opaque cursor pointing to a position in the result set, ensuring consistent paging even when data changes.
Question 47: Which HTTP method is used to make a partial update to an existing resource?
- PUT
- PATCH (Correct answer)
- POST
- DELETE
Correct answer: PATCH
PATCH sends only the fields that need to be changed, unlike PUT which replaces the entire resource.
Question 48: What is the role of 'examples' in an OpenAPI specification?
- Set rate limit values
- Define performance benchmarks
- Show real API traffic logs
- Provide sample request and response payloads to help developers understand expected data (Correct answer)
Correct answer: Provide sample request and response payloads to help developers understand expected data
Examples in OpenAPI specs show concrete sample payloads for requests and responses, making documentation more useful and enabling mock server generation.
Question 49: In test double terminology, what is a 'fake'?
- A stub that only responds to GET requests and ignores all others
- An invalid API response deliberately crafted to trigger error handling
- A recorded HTTP response from a real API that is replayed during tests
- A working but simplified implementation that behaves correctly yet is unsuitable for production (Correct answer)
Correct answer: A working but simplified implementation that behaves correctly yet is unsuitable for production
A fake is a lightweight working implementation (such as an in-memory database) that functions correctly in tests but lacks the robustness needed for production.
Question 50: Which HTTP header is used by APIs to indicate which version is being served?
- Content-Type
- Accept-Encoding
- X-API-Version or a custom versioning header (Correct answer)
- Authorization
Correct answer: X-API-Version or a custom versioning header
Custom headers like X-API-Version or response headers indicating the current API version allow clients to detect which version they are communicating with.
API Testing Certification Exam
The API Testing Certification Exam exam validates essential knowledge and skills required for certification or licensure in this field.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds