
EC-CouncilCloud Security Essentials
Domain 5Objective 4
API Security and Integration Best Practices CSE Practice Questions (Page 4)
Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.
57questions here
12free pages
10concepts
Questions 16–20
- 16
Why is logging API requests important for security?
Select an answer first - 17
Why is input validation essential for API security?
Select an answer first - 18
A developer is building a cloud API that accepts a JSON payload containing a 'username' field. The field is later used in a SQL query. The team wants to prevent SQL injection. Which approach is the most effective?
Select an answer first - 19
An internal API is used by multiple backend services. The security team wants to ensure that only authorized services can call the API and that each service is identified. They also want to prevent one service from overwhelming the API. Which mechanism should they use?
Select an answer first - 20
A public API is being targeted by a distributed denial-of-service (DDoS) attack. The attack uses many distributed IP addresses, making IP-based rate limiting ineffective. The API also must remain available to legitimate users. Which additional control should the team implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.