
EC-CouncilCloud Security Essentials
Domain 5Objective 4
API Security and Integration Best Practices CSE Practice Questions (Page 10)
Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.
57questions here
12free pages
10concepts
Questions 46–50
- 46
A cloud API supports both authenticated and unauthenticated endpoints. The unauthenticated endpoints are used for public information, but they are being abused to launch DDoS attacks. The operations team wants to protect the API without affecting legitimate users. Which strategy is most effective?
Select an answer first - 47
A developer is building a cloud API that accepts JSON payloads. During a security review, the reviewer notes that the API directly inserts user-supplied fields into a SQL query and also returns raw error messages to the client. Which two changes should the developer prioritize?
Select an answer first - 48
An API provider is planning to introduce a breaking change to its API. The provider wants to minimize disruption for existing clients while ensuring that the new version is secure. Which strategy should the provider adopt?
Select an answer first - 49
A multinational company's API processes personal data of EU citizens. The API is hosted in a US cloud region. The compliance team is concerned about GDPR. What is the most appropriate action?
Select an answer first - 50
A company's API stores personal data and is subject to both GDPR and internal governance policies. The governance team requires that all data access be logged and that logs be retained for at least one year. The security team wants to minimize the risk of log tampering. Which approach should they implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.