← All API Flashcard Decks

Mixed Deck — All API Topics Flashcards

100 cards from real API practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All API Topics flashcards as text
  1. What is the purpose of the 'record and replay' feature found in API mocking tools?

    Answer: Capturing real HTTP interactions with an actual API and replaying them as mock responses in subsequent tests

    Record and replay captures live HTTP traffic from a real API and uses those recordings as mock responses, ensuring that mock data is realistic and matches actual API behavior.

  2. Which HTTP header is used to send a Bearer token in API requests?

    Answer: Authorization

    Bearer tokens are sent in the Authorization header using the format 'Authorization: Bearer '.

  3. What is a GraphQL 'schema' used for?

    Answer: Describing all available types, queries, mutations, and subscriptions in the API

    The GraphQL schema is the contract that defines every type, field, query, mutation, and subscription the API exposes.

  4. Which HTTP status code means 'No Content' after a successful DELETE?

    Answer: 204

    204 No Content is commonly returned after a successful DELETE when there is no body to return.

  5. What does the Apdex score measure in API performance monitoring?

    Answer: User satisfaction based on response time thresholds

    Apdex (Application Performance Index) is a standardized score from 0–1 measuring user satisfaction by bucketing response times into Satisfied, Tolerating, and Frustrated.

  6. Which Python library is commonly used for writing automated REST API tests?

    Answer: Requests + PyTest

    The `requests` library handles HTTP calls while `pytest` provides the test framework, making them the standard Python combo for API test automation.

  7. What is a GraphQL 'fragment' used for in testing and development?

    Answer: Reusing a set of fields across multiple queries to reduce duplication

    GraphQL fragments define reusable sets of fields that can be included in multiple queries, reducing repetition and keeping test queries DRY.

  8. Which variable is provided by default for environment variables in Jenkins Pipeline?

    Answer: env

    In Jenkins Pipeline scripts, the `env` global variable is automatically provided and serves as a map-like object to access and manipulate environment variables. You can read existing environment variables (e.g., `env.BUILD_NUMBER`) or set new ones (e.g., `env.MY_VAR = 'value'`) using this variable within your pipeline stages, making it essential for managing build environments.

  9. Which tool can be used to run REST API tests from the command line using a collection file?

    Answer: Newman

    Newman is Postman's CLI runner that executes Postman collection files from the command line or CI pipelines.

  10. What is the difference between a GraphQL 'query' and a 'mutation'?

    Answer: Queries read data; mutations create, update, or delete data

    In GraphQL, queries are read operations (analogous to REST GET) while mutations modify server-side data (analogous to REST POST/PUT/DELETE).

  11. Which REST API testing concept ensures the same request always produces the same result?

    Answer: Idempotency

    Idempotency means that making the same API call multiple times produces the same result as making it once.

  12. What does the 'Accept-Version' header allow in API requests?

    Answer: Requesting a specific API version via headers

    The Accept-Version (or similar custom) header enables clients to request a specific API version without modifying the URL.

  13. What does 'mass assignment' vulnerability in APIs involve?

    Answer: Binding user input directly to internal object properties without filtering

    Mass assignment occurs when an API binds client-provided data directly to object properties, allowing attackers to set privileged fields.

  14. What does 'contract testing' verify in a microservices API architecture?

    Answer: Consumer and provider agree on the API interface format

    Contract testing ensures the API's actual responses conform to the agreed contract the consumer depends on, catching breaking changes early.

  15. According to the 'test pyramid' principle, how should API mock usage be distributed across testing levels?

    Answer: Use mocks extensively in fast unit tests to isolate components, less so in integration tests, and minimally in end-to-end tests

    The test pyramid recommends heavy mock usage in the large base of fast unit tests, reduced mocking in integration tests, and minimal mocking in the small top layer of end-to-end tests that validate real-world behavior.

  16. Which part of a JWT contains the claims about the entity?

    Answer: Payload

    The payload section of a JWT contains the claims, which are statements about the entity (typically the user) and additional metadata.

  17. Which tool is commonly used for API security scanning and vulnerability detection?

    Answer: OWASP ZAP

    OWASP ZAP (Zed Attack Proxy) is an open-source security scanner that can intercept, analyze, and attack API endpoints to find vulnerabilities.

  18. What is the 'N+1 query problem' in GraphQL testing?

    Answer: Fetching a list then making N additional queries for each item's related data

    The N+1 problem occurs when a GraphQL resolver fetches a list (1 query) then makes a separate database call for each item (N queries), severely hurting performance.

  19. Which HTTP header specifies the format of the request body?

    Answer: Content-Type

    The Content-Type header tells the server what format the request body is in, such as application/json.

  20. What does the HTTP status code 404 mean in a REST API response?

    Answer: Not Found

    404 Not Found indicates that the requested resource does not exist on the server.