Security & Access Management Flashcards
7 cards from real POC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security & Access Management flashcards as text
What is the risk of using Python's `pickle` module to deserialize data received from an untrusted source?
Answer: It can execute arbitrary code during deserialization
`pickle` can execute arbitrary Python code embedded in a malicious payload during deserialization, making it dangerous with untrusted data.
Which environment variable handling approach is most secure when storing API keys in a Python application?
Answer: Load them via `os.environ` from environment variables set outside the codebase
Loading secrets from environment variables keeps them out of source code and version control, reducing the risk of accidental exposure.
What does `hashlib.pbkdf2_hmac('sha256', password, salt, 100000)` accomplish?
Answer: Derives a key from a password using 100,000 iterations to resist brute-force attacks
PBKDF2 applies HMAC-SHA256 many times (100,000 iterations here) to make password cracking computationally expensive.
Which Python built-in can accidentally expose sensitive data if called on an object that implements `__repr__`?
Answer: repr()
`repr()` invokes `__repr__`, which may include sensitive fields like passwords or tokens if not deliberately excluded from the representation.
When creating a temporary file with sensitive data in Python, which function is preferred to prevent race conditions?
Answer: tempfile.mkstemp()
`tempfile.mkstemp()` atomically creates and opens a uniquely named temp file, avoiding TOCTOU race conditions that plague manual temp file creation.
What does RBAC stand for in the context of Python access control frameworks?
Answer: Role-Based Access Control
Role-Based Access Control assigns permissions to roles rather than individual users, simplifying management of who can perform which actions.
Which Python decorator pattern is commonly used to enforce authentication on Flask or FastAPI route handlers?
Answer: @login_required or @Depends(get_current_user)
In Flask, `@login_required` wraps route handlers to check authentication; in FastAPI, `Depends(get_current_user)` injects and verifies the current user before the handler runs.