← All HCT Flashcard Decks

Security & Access Management Flashcards

7 cards from real HCT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security & Access Management flashcards as text
  1. A developer is using the HubSpot API to sync CRM data with an external system. What credential type should they use to authenticate API calls securely?

    Answer: A private app access token scoped to necessary permissions

    Private apps generate scoped access tokens that follow least-privilege principles, replacing the deprecated master API key.

  2. What is the primary security advantage of OAuth 2.0 app authentication over a static private app token in HubSpot?

    Answer: OAuth allows the integration to act on behalf of individual users with their own permissions

    OAuth 2.0 allows third-party apps to act as specific HubSpot users, scoping actions to that user's permissions rather than a single service account.

  3. A HubSpot portal has SSO configured. What happens if the SSO identity provider is temporarily down?

    Answer: All portal access is blocked until SSO is restored

    When SSO is enforced, HubSpot requires the identity provider for authentication; if the provider is unavailable, users cannot log in until it is restored.

  4. Which HubSpot feature allows automatic provisioning and deprovisioning of user accounts when employees join or leave an organization?

    Answer: SCIM (System for Cross-domain Identity Management)

    SCIM integration syncs HubSpot user accounts with an identity directory, automatically adding or removing users as their status changes.

  5. A trainer is advising a client to rotate their private app access tokens. How should this be handled in HubSpot?

    Answer: Use the 'Rotate token' option in the private app settings to generate a new token

    HubSpot private apps include a token rotation feature that generates a new access token while automatically invalidating the previous one.

  6. What scopes should be requested when creating a HubSpot private app that only needs to read and update contact records?

    Answer: crm.objects.contacts.read and crm.objects.contacts.write

    HubSpot's private app scopes use a granular naming convention; read and write scopes for contacts are crm.objects.contacts.read and crm.objects.contacts.write.

  7. A HubSpot admin wants to restrict portal access to users connecting from the company's corporate network only. Which feature addresses this?

    Answer: IP allowlist configuration in Security settings

    HubSpot's IP allowlist feature (available on Enterprise plans) blocks login attempts from IP addresses outside the approved list.