Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 5Objective 4

API Security and Integration Best Practices CSE Practice Questions (Page 3)

Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.

57questions here
12free pages
10concepts

Questions 11–15

  1. 11application · medium

    A company exposes a public REST API for its mobile app. The security team requires that each request be authenticated without storing session state on the server, and that the API reject requests that originate from a client that has been compromised and is making excessive calls. Which combination of controls should the team implement?

    Select an answer first
  2. 12expert · hard

    A company is integrating a third-party API that occasionally returns malformed JSON and has a history of slow responses. The integration must be resilient and must not leak internal error details to end users. Which approach should the developer take?

    Select an answer first
  3. 13application · medium

    A startup is building a public API for its new service. The team wants to implement a security baseline. Which combination of controls is most effective?

    Select an answer first
  4. 14expert · hard · select all that apply

    A security team is planning a penetration test for a public API. The test must be comprehensive and minimize risk to production data. Which of the following practices should be included? (Select all that apply.)

    Select an answer first
  5. 15foundation · easy

    When integrating an API with a cloud service, what is a best practice for handling errors?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.