API Security interview questions — Medium

347 medium-level API Security questions from our API Testing bank, each with the correct answer and an explanation of why it is correct.

What this covers

API Security appears throughout API Testing interviews. At medium level, interviewers are typically checking that you have used it in practice: what you configured, what broke, and how you knew it worked. Work through these, then explain your answer out loud; the second part is what interviews actually test.

20 example questions

  1. 1. "Insecure Direct Object Reference: accessing others' data via IDs" — in API Security, this describes which of the following?

    • A. Refresh token.
    • B. MTLS.
    • C. HMAC signature.
    • D. IDOR.correct

    Why: IDOR: Insecure Direct Object Reference: accessing others' data via IDs.

  2. 2. "Hash-based signature proving request integrity and origin" — in API Security, this describes which of the following?

    • A. Scope.
    • B. Bearer token.
    • C. HMAC signature.correct
    • D. OWASP API Security Top 10.

    Why: HMAC signature: Hash-based signature proving request integrity and origin.

  3. 3. "JWT claim defining when the token becomes invalid" — in API Security, this describes which of the following?

    • A. MTLS.
    • B. Token expiry (exp claim).correct
    • C. Penetration testing.
    • D. Bearer token.

    Why: token expiry (exp claim): JWT claim defining when the token becomes invalid.

  4. 4. "Permission granted to a token limiting what it can do" — in API Security, this describes which of the following?

    • A. Refresh token.
    • B. Scope.correct
    • C. Bearer token.
    • D. Token expiry (exp claim).

    Why: scope: Permission granted to a token limiting what it can do.

  5. 5. "Authorized simulated attack to find exploitable weaknesses" — in API Security, this describes which of the following?

    • A. Scope.
    • B. Penetration testing.correct
    • C. IDOR.
    • D. Refresh token.

    Why: penetration testing: Authorized simulated attack to find exploitable weaknesses.

  6. 6. "Mutual TLS where client and server both present certificates" — in API Security, this describes which of the following?

    • A. MTLS.correct
    • B. Penetration testing.
    • C. Token expiry (exp claim).
    • D. Refresh token.

    Why: mTLS: Mutual TLS where client and server both present certificates.

  7. 7. Which of the following statements about API Security is TRUE?

    • A. API keys are stronger and more granular than OAuth user tokens in every case.
    • B. A JWT consists of a header, payload, and signature separated by dots.correct
    • C. JWT payloads are encrypted so their contents can never be read.
    • D. Storing passwords in a JWT payload is a recommended practice.

    Why: Signatures let servers verify tokens without a database lookup.

  8. 8. "Credential presented in the Authorization header to access an API" — in API Security, this describes which of the following?

    • A. Refresh token.
    • B. HMAC signature.
    • C. Penetration testing.
    • D. Bearer token.correct

    Why: Bearer token: Credential presented in the Authorization header to access an API.

  9. 9. Which statement correctly describes API Security?

    • A. OAuth 2.0 requires sharing the user's password with every client application.
    • B. BOLA vulnerabilities are prevented automatically by using HTTPS.
    • C. A JWT consists of a header, payload, and signature separated by dots.correct
    • D. Storing passwords in a JWT payload is a recommended practice.

    Why: Signatures let servers verify tokens without a database lookup.

  10. 10. Identify the accurate statement about API Security:

    • A. API keys are stronger and more granular than OAuth user tokens in every case.
    • B. Expired tokens should still be accepted for a grace period of several days by default.
    • C. Rate limiting should respond with HTTP 200 when the limit is exceeded.
    • D. The client credentials grant is used for machine-to-machine authentication without a user.correct

    Why: Service-to-service calls use client_id/client_secret for tokens.

  11. 11. In API Security, which of the following is described as: "Long-lived credential exchanged for new access tokens"?

    • A. Penetration testing.
    • B. IDOR.
    • C. Refresh token.correct
    • D. OWASP API Security Top 10.

    Why: refresh token: Long-lived credential exchanged for new access tokens.

  12. 12. In API Security, which of the following is described as: "Hash-based signature proving request integrity and origin"?

    • A. OWASP API Security Top 10.
    • B. Refresh token.
    • C. Scope.
    • D. HMAC signature.correct

    Why: HMAC signature: Hash-based signature proving request integrity and origin.

  13. 13. Which API Security concept matches this description: "Insecure Direct Object Reference: accessing others' data via IDs"?

    • A. Token expiry (exp claim).
    • B. Scope.
    • C. IDOR.correct
    • D. HMAC signature.

    Why: IDOR: Insecure Direct Object Reference: accessing others' data via IDs.

  14. 14. Which API Security concept matches this description: "Credential presented in the Authorization header to access an API"?

    • A. Bearer token.correct
    • B. Token expiry (exp claim).
    • C. Scope.
    • D. Penetration testing.

    Why: Bearer token: Credential presented in the Authorization header to access an API.

  15. 15. Which API Security concept matches this description: "Mutual TLS where client and server both present certificates"?

    • A. Refresh token.
    • B. MTLS.correct
    • C. Scope.
    • D. Token expiry (exp claim).

    Why: mTLS: Mutual TLS where client and server both present certificates.

  16. 16. In API Security, which of the following is described as: "Insecure Direct Object Reference: accessing others' data via IDs"?

    • A. Penetration testing.
    • B. IDOR.correct
    • C. Refresh token.
    • D. OWASP API Security Top 10.

    Why: IDOR: Insecure Direct Object Reference: accessing others' data via IDs.

  17. 17. Which API Security concept matches this description: "Permission granted to a token limiting what it can do"?

    • A. HMAC signature.
    • B. MTLS.
    • C. Scope.correct
    • D. IDOR.

    Why: scope: Permission granted to a token limiting what it can do.

  18. 18. In API Security, which of the following is described as: "Permission granted to a token limiting what it can do"?

    • A. Scope.correct
    • B. OWASP API Security Top 10.
    • C. Token expiry (exp claim).
    • D. Penetration testing.

    Why: scope: Permission granted to a token limiting what it can do.

  19. 19. Which API Security concept matches this description: "Industry list of the most critical API vulnerabilities"?

    • A. Penetration testing.
    • B. OWASP API Security Top 10.correct
    • C. Scope.
    • D. MTLS.

    Why: OWASP API Security Top 10: Industry list of the most critical API vulnerabilities.

  20. 20. Which API Security concept matches this description: "Hash-based signature proving request integrity and origin"?

    • A. Penetration testing.
    • B. HMAC signature.correct
    • C. OWASP API Security Top 10.
    • D. MTLS.

    Why: HMAC signature: Hash-based signature proving request integrity and origin.

Related API Testing topics