
EC-CouncilCloud Security Essentials
Domain 5Objective 4
API Security and Integration Best Practices CSE Practice Questions (Page 5)
Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.
57questions here
12free pages
10concepts
Questions 21–25
- 21
A healthcare API transmits patient records between a cloud backend and a partner's on-premises system. The partner's system does not support TLS 1.3. What is the best way to secure data in transit?
Select an answer first - 22
Which protocol is commonly used to encrypt data in transit for APIs?
Select an answer first - 23
What is the purpose of penetration testing an API?
Select an answer first - 24
An organization is about to release a new public API. The security team wants to identify vulnerabilities before production. Which testing approach is most comprehensive?
Select an answer first - 25
A public API accepts user comments that are later displayed to other users. The security team is concerned about stored XSS attacks. Which input handling strategy should the API implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.