API Security interview questions — Hard
175 hard-level API Security questions from our API Testing bank, each with the correct answer and an explanation of why it is correct.
What this covers
API Security appears throughout API Testing interviews. At hard level, interviewers are typically checking depth under pressure — edge cases, failure modes, performance characteristics, and the trade-offs you accepted. Work through these, then explain your answer out loud; the second part is what interviews actually test.
4 example questions
1. Regarding API Security, which of the following is a false statement?
- A. API keys are stronger and more granular than OAuth user tokens in every case.correct
- B. OAuth 2.0 is an authorization framework where clients obtain access tokens to call APIs.
- C. API keys identify the calling application but are weaker than user-level OAuth tokens.
- D. The client credentials grant is used for machine-to-machine authentication without a user.
Why: The selected statement is false. The other options are accurate statements about API Security.
2. Which of the following statements about API Security is FALSE?
- A. JWTs are encoded, not encrypted: anyone can decode and read the payload.
- B. Security tests should confirm sensitive data is never exposed in URLs or logs.
- C. OAuth 2.0 is an authorization framework where clients obtain access tokens to call APIs.
- D. API keys are stronger and more granular than OAuth user tokens in every case.correct
Why: The selected statement is false. The other options are accurate statements about API Security.
3. Which statement about API Security is NOT correct?
- A. API keys identify the calling application but are weaker than user-level OAuth tokens.
- B. Mass assignment vulnerabilities let clients set fields they should not control, like role=admin.
- C. Broken Object Level Authorization (BOLA) means users can access objects belonging to others by changing IDs.
- D. API keys are stronger and more granular than OAuth user tokens in every case.correct
Why: The selected statement is false. The other options are accurate statements about API Security.
4. Identify the INCORRECT statement about API Security:
- A. Rate limiting protects APIs from abuse and should return 429 when exceeded.
- B. Expired tokens should still be accepted for a grace period of several days by default.correct
- C. API keys identify the calling application but are weaker than user-level OAuth tokens.
- D. Mass assignment vulnerabilities let clients set fields they should not control, like role=admin.
Why: The selected statement is false. The other options are accurate statements about API Security.