API Security interview questions — Easy

175 easy-level API Security questions from our API Testing bank, each with the correct answer and an explanation of why it is correct.

What this covers

API Security appears throughout API Testing interviews. At easy level, interviewers are typically checking that you know the fundamentals and can describe them precisely — definitions, defaults, and the basic mechanics. Work through these, then explain your answer out loud; the second part is what interviews actually test.

20 example questions

  1. 1. In the context of API Security, OWASP API Security Top 10 is best described as:

    • A. JWT claim defining when the token becomes invalid.
    • B. Authorized simulated attack to find exploitable weaknesses.
    • C. Insecure Direct Object Reference: accessing others' data via IDs.
    • D. Industry list of the most critical API vulnerabilities.correct

    Why: OWASP API Security Top 10: Industry list of the most critical API vulnerabilities.

  2. 2. Which of the following best describes OWASP API Security Top 10 in API Security?

    • A. Long-lived credential exchanged for new access tokens.
    • B. JWT claim defining when the token becomes invalid.
    • C. Credential presented in the Authorization header to access an API.
    • D. Industry list of the most critical API vulnerabilities.correct

    Why: OWASP API Security Top 10: Industry list of the most critical API vulnerabilities.

  3. 3. Which of the following best describes penetration testing in API Security?

    • A. Long-lived credential exchanged for new access tokens.
    • B. Mutual TLS where client and server both present certificates.
    • C. Permission granted to a token limiting what it can do.
    • D. Authorized simulated attack to find exploitable weaknesses.correct

    Why: penetration testing: Authorized simulated attack to find exploitable weaknesses.

  4. 4. In API Security, what does penetration testing do or refer to?

    • A. JWT claim defining when the token becomes invalid.
    • B. Authorized simulated attack to find exploitable weaknesses.correct
    • C. Hash-based signature proving request integrity and origin.
    • D. Credential presented in the Authorization header to access an API.

    Why: penetration testing: Authorized simulated attack to find exploitable weaknesses.

  5. 5. Which of the following best describes Bearer token in API Security?

    • A. Credential presented in the Authorization header to access an API.correct
    • B. Permission granted to a token limiting what it can do.
    • C. Long-lived credential exchanged for new access tokens.
    • D. Authorized simulated attack to find exploitable weaknesses.

    Why: Bearer token: Credential presented in the Authorization header to access an API.

  6. 6. In API Security, what does OWASP API Security Top 10 do or refer to?

    • A. Industry list of the most critical API vulnerabilities.correct
    • B. Authorized simulated attack to find exploitable weaknesses.
    • C. Credential presented in the Authorization header to access an API.
    • D. Insecure Direct Object Reference: accessing others' data via IDs.

    Why: OWASP API Security Top 10: Industry list of the most critical API vulnerabilities.

  7. 7. In API Security, what does token expiry (exp claim) do or refer to?

    • A. Permission granted to a token limiting what it can do.
    • B. JWT claim defining when the token becomes invalid.correct
    • C. Authorized simulated attack to find exploitable weaknesses.
    • D. Long-lived credential exchanged for new access tokens.

    Why: token expiry (exp claim): JWT claim defining when the token becomes invalid.

  8. 8. Which of the following best describes HMAC signature in API Security?

    • A. Authorized simulated attack to find exploitable weaknesses.
    • B. Insecure Direct Object Reference: accessing others' data via IDs.
    • C. Mutual TLS where client and server both present certificates.
    • D. Hash-based signature proving request integrity and origin.correct

    Why: HMAC signature: Hash-based signature proving request integrity and origin.

  9. 9. Which of the following best describes token expiry (exp claim) in API Security?

    • A. Credential presented in the Authorization header to access an API.
    • B. Long-lived credential exchanged for new access tokens.
    • C. Industry list of the most critical API vulnerabilities.
    • D. JWT claim defining when the token becomes invalid.correct

    Why: token expiry (exp claim): JWT claim defining when the token becomes invalid.

  10. 10. What is the purpose of token expiry (exp claim) in API Security?

    • A. Long-lived credential exchanged for new access tokens.
    • B. JWT claim defining when the token becomes invalid.correct
    • C. Credential presented in the Authorization header to access an API.
    • D. Hash-based signature proving request integrity and origin.

    Why: token expiry (exp claim): JWT claim defining when the token becomes invalid.

  11. 11. What is the purpose of OWASP API Security Top 10 in API Security?

    • A. Hash-based signature proving request integrity and origin.
    • B. Industry list of the most critical API vulnerabilities.correct
    • C. Mutual TLS where client and server both present certificates.
    • D. Permission granted to a token limiting what it can do.

    Why: OWASP API Security Top 10: Industry list of the most critical API vulnerabilities.

  12. 12. What is the purpose of IDOR in API Security?

    • A. Credential presented in the Authorization header to access an API.
    • B. Insecure Direct Object Reference: accessing others' data via IDs.correct
    • C. Authorized simulated attack to find exploitable weaknesses.
    • D. Industry list of the most critical API vulnerabilities.

    Why: IDOR: Insecure Direct Object Reference: accessing others' data via IDs.

  13. 13. Which of the following best describes IDOR in API Security?

    • A. Insecure Direct Object Reference: accessing others' data via IDs.correct
    • B. Hash-based signature proving request integrity and origin.
    • C. Mutual TLS where client and server both present certificates.
    • D. JWT claim defining when the token becomes invalid.

    Why: IDOR: Insecure Direct Object Reference: accessing others' data via IDs.

  14. 14. What is the purpose of penetration testing in API Security?

    • A. Industry list of the most critical API vulnerabilities.
    • B. JWT claim defining when the token becomes invalid.
    • C. Credential presented in the Authorization header to access an API.
    • D. Authorized simulated attack to find exploitable weaknesses.correct

    Why: penetration testing: Authorized simulated attack to find exploitable weaknesses.

  15. 15. Which of the following best describes scope in API Security?

    • A. Hash-based signature proving request integrity and origin.
    • B. Permission granted to a token limiting what it can do.correct
    • C. Authorized simulated attack to find exploitable weaknesses.
    • D. JWT claim defining when the token becomes invalid.

    Why: scope: Permission granted to a token limiting what it can do.

  16. 16. In API Security, what does IDOR do or refer to?

    • A. Authorized simulated attack to find exploitable weaknesses.
    • B. Mutual TLS where client and server both present certificates.
    • C. Insecure Direct Object Reference: accessing others' data via IDs.correct
    • D. Hash-based signature proving request integrity and origin.

    Why: IDOR: Insecure Direct Object Reference: accessing others' data via IDs.

  17. 17. In API Security, what does Bearer token do or refer to?

    • A. Credential presented in the Authorization header to access an API.correct
    • B. Authorized simulated attack to find exploitable weaknesses.
    • C. Permission granted to a token limiting what it can do.
    • D. Industry list of the most critical API vulnerabilities.

    Why: Bearer token: Credential presented in the Authorization header to access an API.

  18. 18. What is the purpose of scope in API Security?

    • A. Permission granted to a token limiting what it can do.correct
    • B. Authorized simulated attack to find exploitable weaknesses.
    • C. Hash-based signature proving request integrity and origin.
    • D. Long-lived credential exchanged for new access tokens.

    Why: scope: Permission granted to a token limiting what it can do.

  19. 19. What is the purpose of HMAC signature in API Security?

    • A. Permission granted to a token limiting what it can do.
    • B. Authorized simulated attack to find exploitable weaknesses.
    • C. Hash-based signature proving request integrity and origin.correct
    • D. Credential presented in the Authorization header to access an API.

    Why: HMAC signature: Hash-based signature proving request integrity and origin.

  20. 20. What is the purpose of refresh token in API Security?

    • A. Mutual TLS where client and server both present certificates.
    • B. Long-lived credential exchanged for new access tokens.correct
    • C. Hash-based signature proving request integrity and origin.
    • D. Authorized simulated attack to find exploitable weaknesses.

    Why: refresh token: Long-lived credential exchanged for new access tokens.

Related API Testing topics