โ† All API Flashcard Decks

API Authentication & Security Testing Flashcards

6 cards from real API practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 API Authentication & Security Testing flashcards as text
  1. What does OAuth 2.0 authorization code flow primarily protect against compared to the implicit flow?

    Answer: Exposing access tokens in the browser URL

    The authorization code flow exchanges a short-lived code server-side for tokens, preventing access tokens from appearing in browser history or logs.

  2. Which OWASP API Security risk occurs when an API returns more data than the client needs?

    Answer: Excessive Data Exposure

    Excessive Data Exposure happens when an API returns full object data, relying on the client to filter, which risks leaking sensitive fields.

  3. What is the recommended way to store API keys in client-side applications?

    Answer: Store them in environment variables or a secrets manager, never in frontend code

    API keys must never be exposed in client-side code; they should be kept in server-side environment variables or a secrets manager.

  4. What does the term 'mass assignment' vulnerability mean in API security?

    Answer: An API blindly binding user-supplied fields to internal object properties

    Mass assignment occurs when an API maps all client-provided fields to a model without filtering, letting attackers set privileged fields like 'isAdmin'.

  5. Which tool is commonly used for API security scanning and vulnerability detection?

    Answer: OWASP ZAP

    OWASP ZAP (Zed Attack Proxy) is an open-source security scanner that can intercept, analyze, and attack API endpoints to find vulnerabilities.

  6. What is the primary purpose of certificate pinning in API security?

    Answer: Prevent man-in-the-middle attacks by validating the server's exact certificate

    Certificate pinning hardcodes an expected server certificate or public key in the client, rejecting connections if the certificate doesn't match.