← All API Flashcard Decks

API Authentication & Security Testing Flashcards

6 cards from real API practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 API Authentication & Security Testing flashcards as text
  1. What does JWT stand for in the context of API authentication?

    Answer: JSON Web Token

    JWT (JSON Web Token) is a compact, URL-safe token format used to securely transmit claims between client and server.

  2. Which part of a JWT contains the user claims and data?

    Answer: Payload

    The JWT Payload is the middle Base64URL-encoded section that contains the claims, such as user ID, roles, and expiration time.

  3. What is CORS and why is it important in API security testing?

    Answer: A browser mechanism controlling cross-origin requests

    CORS (Cross-Origin Resource Sharing) is a browser policy that controls which origins can call an API, preventing unauthorized cross-site requests.

  4. Which HTTP status code does an API return when a request lacks valid authentication credentials?

    Answer: 401 Unauthorized

    401 Unauthorized means the request requires authentication that was not provided or is invalid.

  5. What is a replay attack in the context of API security?

    Answer: Sending the same valid request multiple times to exploit the API

    A replay attack reuses a captured valid API request (including its token) to perform unauthorized actions.

  6. Which security testing technique sends unexpected or malformed data to an API to discover vulnerabilities?

    Answer: Fuzzing

    Fuzzing (or fuzz testing) feeds random, invalid, or malformed inputs to an API to uncover crashes, errors, and security flaws.