โ† All API Flashcard Decks

API Authentication & Security Testing Flashcards

6 cards from real API practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 API Authentication & Security Testing flashcards as text
  1. Which authentication mechanism uses a Bearer token included in the Authorization header?

    Answer: OAuth 2.0 / JWT

    OAuth 2.0 and JWT-based flows pass an access token as a Bearer token in the Authorization header.

  2. What is an API key primarily used for in API security testing?

    Answer: Identifying and authenticating the calling application

    An API key is a unique identifier passed with requests to authenticate the client application making the call.

  3. Which OWASP API Security risk involves an attacker accessing another user's data by manipulating object IDs?

    Answer: Broken Object Level Authorization

    Broken Object Level Authorization (BOLA/IDOR) occurs when APIs fail to verify the caller owns the object they are requesting.

  4. What does HTTPS ensure during API communication?

    Answer: Encryption of data in transit

    HTTPS (HTTP over TLS) encrypts all data exchanged between client and server, preventing eavesdropping and tampering.

  5. Which attack involves sending malicious data in API input fields to manipulate backend database queries?

    Answer: SQL Injection

    SQL Injection exploits APIs that pass unsanitized user input directly into SQL queries, allowing attackers to read or alter the database.

  6. What is the purpose of rate limiting in API security?

    Answer: Prevent abuse by limiting the number of requests per client

    Rate limiting restricts how many requests a client can make in a time window, protecting the API from brute force and DoS attacks.