
EC-CouncilCloud Security Essentials
Domain 5Objective 4
API Security and Integration Best Practices CSE Practice Questions (Page 11)
Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.
57questions here
12free pages
10concepts
Questions 51–55
- 51
An API accepts a file upload from users. The file is stored in cloud storage and later processed. What is the most important validation to prevent malicious file uploads?
Select an answer first - 52
A financial services company must audit all access to its customer data API. The compliance team requires a record of who accessed what data, when, and from where. Which logging practice is most critical?
Select an answer first - 53
A company is designing a new public API. The security team wants to implement a defense-in-depth strategy. Which combination of controls provides the most comprehensive protection?
Select an answer first - 54
A company's internal API is accessed by multiple internal services. The security team wants to ensure that only authorized services can call the API, and that the communication is encrypted. What is the best approach?
Select an answer first - 55
A company is designing an API for a partner integration. The partners are external organizations, and each partner has multiple users. The company wants to authenticate the partner organization and also authorize individual users within that organization. They also need to revoke access for a single user quickly. Which approach should they choose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.