
EC-CouncilCloud Security Essentials
Domain 5Objective 4
API Security and Integration Best Practices CSE Practice Questions (Page 8)
Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.
57questions here
12free pages
10concepts
Questions 36–40
- 36
What is the primary purpose of using OAuth2 in API authentication and authorization?
Select an answer first - 37
A security team is conducting a penetration test on a new API. They have a limited time window and must prioritize testing for the most critical vulnerabilities. The API accepts JSON input and uses JWT for authentication. Which testing activity should they prioritize?
Select an answer first - 38
A cloud API processes credit card data and must comply with PCI DSS. The API uses OAuth2 tokens for authentication. What is the most important control to ensure compliance?
Select an answer first - 39
A multinational company's API processes personal data of EU citizens. The legal team requires that the API implementation demonstrate compliance with GDPR, including the ability to provide audit logs and ensure data protection. Which measure should the company implement?
Select an answer first - 40
A company exposes a public REST API for its mobile app. The API currently uses long-lived API keys passed in the Authorization header. After a security review, the team decides to implement OAuth2 with short-lived access tokens and refresh tokens. What additional control is most important to prevent token theft from the mobile app?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.