← All POC Flashcard Decks

Security & Access Management Flashcards

7 cards from real POC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security & Access Management flashcards as text
  1. Which Python module provides the `getpass()` function to securely prompt for a password without echoing input?

    Answer: getpass

    The `getpass` module provides `getpass()` which prompts for a password without displaying characters on the terminal.

  2. What does the `secrets` module's `token_urlsafe(32)` generate?

    Answer: A URL-safe base64-encoded random token of 32 bytes

    `token_urlsafe(n)` generates a URL-safe base64-encoded string from `n` random bytes, suitable for session tokens and CSRF protection.

  3. When using Python's `ssl` module, what does `ssl.CERT_REQUIRED` enforce?

    Answer: The server must present a certificate signed by a trusted CA

    `ssl.CERT_REQUIRED` causes the SSL handshake to fail unless the peer presents a valid certificate signed by a trusted certificate authority.

  4. Which attack does parameterized SQL queries in Python's `sqlite3` module primarily prevent?

    Answer: SQL injection

    Parameterized queries separate SQL code from user-supplied data, preventing SQL injection by treating input as literal values rather than executable code.

  5. What is the purpose of `os.chmod(path, 0o600)` from a security standpoint?

    Answer: Restricts file read/write to the owner only

    Octal `0o600` sets read and write permissions for the owner only, ensuring sensitive files like private keys are not accessible to other users.

  6. Which function in the `hmac` module verifies that two HMAC digests are equal in a timing-safe manner?

    Answer: hmac.compare_digest()

    `hmac.compare_digest()` performs a constant-time comparison to prevent timing attacks that could leak information about the secret.

  7. In Python's `cryptography` library, what is a Fernet token?

    Answer: An AES-128-CBC encrypted and HMAC-authenticated message

    Fernet uses AES-128-CBC for encryption and HMAC-SHA256 for authentication, then base64url-encodes the result into a single token.