API Security interview questions

36 API Security questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What is Rate limiting?

Junior
  1. A.Broken Object Level Authorization, the top API risk where an API fails to check object ownership
  2. B.an API returning more fields than the client needs, leaking sensitive data
  3. C.capping nested query depth to prevent resource-exhaustion denial of service
  4. D.capping how many requests a client may make in a window to curb abuse and brute force

Answer + AI explanation with Pro

2. Which term means: "capping how many requests a client may make in a window to curb abuse and brute force"?

Junior
  1. A.BFLA
  2. B.Rate limiting
  3. C.GraphQL introspection abuse
  4. D.API gateway

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.Rate limiting — binding client JSON to internal fields the caller should not be able to set
  2. B.Rate limiting — capping how many requests a client may make in a window to curb abuse and brute force
  3. C.Rate limiting — entry point that centralizes auth, rate limiting, and routing for backend APIs
  4. D.Rate limiting — validating an HMAC signature on inbound webhooks to confirm they came from the real sender

Answer + AI explanation with Pro

4. What is API key?

Junior
  1. A.querying the GraphQL schema to map and probe an API's full attack surface
  2. B.binding client JSON to internal fields the caller should not be able to set
  3. C.static token identifying and authenticating a calling application to an API
  4. D.capping nested query depth to prevent resource-exhaustion denial of service

Answer + AI explanation with Pro

5. Which term means: "static token identifying and authenticating a calling application to an API"?

Junior
  1. A.API key
  2. B.API gateway
  3. C.GraphQL introspection abuse
  4. D.GraphQL query depth limiting

Answer + AI explanation with Pro

6. Which statement is correct?

Junior
  1. A.API key — static token identifying and authenticating a calling application to an API
  2. B.API key — entry point that centralizes auth, rate limiting, and routing for backend APIs
  3. C.API key — Broken Object Level Authorization, the top API risk where an API fails to check object ownership
  4. D.API key — querying the GraphQL schema to map and probe an API's full attack surface

Answer + AI explanation with Pro

7. What is Input schema validation?

Junior
  1. A.validating an HMAC signature on inbound webhooks to confirm they came from the real sender
  2. B.rejecting API requests whose body or parameters do not match an expected schema
  3. C.Broken Function Level Authorization where a user invokes privileged operations they should not access
  4. D.querying the GraphQL schema to map and probe an API's full attack surface

Answer + AI explanation with Pro

8. Which term means: "rejecting API requests whose body or parameters do not match an expected schema"?

Junior
  1. A.Input schema validation
  2. B.BOLA
  3. C.Webhook signature verification
  4. D.API gateway

Answer + AI explanation with Pro

9. Which statement is correct?

Junior
  1. A.Input schema validation — capping how many requests a client may make in a window to curb abuse and brute force
  2. B.Input schema validation — rejecting API requests whose body or parameters do not match an expected schema
  3. C.Input schema validation — capping nested query depth to prevent resource-exhaustion denial of service
  4. D.Input schema validation — validating an HMAC signature on inbound webhooks to confirm they came from the real sender

Answer + AI explanation with Pro

10. What is API gateway?

Junior
  1. A.rejecting API requests whose body or parameters do not match an expected schema
  2. B.entry point that centralizes auth, rate limiting, and routing for backend APIs
  3. C.capping how many requests a client may make in a window to curb abuse and brute force
  4. D.signing API requests with a shared secret so the server can verify integrity and origin

Answer + AI explanation with Pro

11. Which term means: "entry point that centralizes auth, rate limiting, and routing for backend APIs"?

Junior
  1. A.API gateway
  2. B.Rate limiting
  3. C.Request signing (HMAC)
  4. D.GraphQL introspection abuse

Answer + AI explanation with Pro

12. Which statement is correct?

Junior
  1. A.API gateway — Broken Object Level Authorization, the top API risk where an API fails to check object ownership
  2. B.API gateway — entry point that centralizes auth, rate limiting, and routing for backend APIs
  3. C.API gateway — binding client JSON to internal fields the caller should not be able to set
  4. D.API gateway — an API returning more fields than the client needs, leaking sensitive data

Answer + AI explanation with Pro

13. What is BOLA?

Mid
  1. A.Broken Object Level Authorization, the top API risk where an API fails to check object ownership
  2. B.binding client JSON to internal fields the caller should not be able to set
  3. C.static token identifying and authenticating a calling application to an API
  4. D.querying the GraphQL schema to map and probe an API's full attack surface

Answer + AI explanation with Pro

14. Which term means: "Broken Object Level Authorization, the top API risk where an API fails to check object ownership"?

Mid
  1. A.GraphQL introspection abuse
  2. B.Webhook signature verification
  3. C.API gateway
  4. D.BOLA

Answer + AI explanation with Pro

15. Which statement is correct?

Mid
  1. A.BOLA — entry point that centralizes auth, rate limiting, and routing for backend APIs
  2. B.BOLA — capping how many requests a client may make in a window to curb abuse and brute force
  3. C.BOLA — Broken Object Level Authorization, the top API risk where an API fails to check object ownership
  4. D.BOLA — capping nested query depth to prevent resource-exhaustion denial of service

Answer + AI explanation with Pro

16. What is Excessive data exposure?

Mid
  1. A.an API returning more fields than the client needs, leaking sensitive data
  2. B.rejecting API requests whose body or parameters do not match an expected schema
  3. C.Broken Object Level Authorization, the top API risk where an API fails to check object ownership
  4. D.capping how many requests a client may make in a window to curb abuse and brute force

Answer + AI explanation with Pro

17. Which term means: "an API returning more fields than the client needs, leaking sensitive data"?

Mid
  1. A.Mass assignment (API)
  2. B.Request signing (HMAC)
  3. C.Excessive data exposure
  4. D.BFLA

Answer + AI explanation with Pro

18. Which statement is correct?

Mid
  1. A.Excessive data exposure — an API returning more fields than the client needs, leaking sensitive data
  2. B.Excessive data exposure — signing API requests with a shared secret so the server can verify integrity and origin
  3. C.Excessive data exposure — validating an HMAC signature on inbound webhooks to confirm they came from the real sender
  4. D.Excessive data exposure — querying the GraphQL schema to map and probe an API's full attack surface

Answer + AI explanation with Pro

19. What is Mass assignment (API)?

Mid
  1. A.capping nested query depth to prevent resource-exhaustion denial of service
  2. B.binding client JSON to internal fields the caller should not be able to set
  3. C.rejecting API requests whose body or parameters do not match an expected schema
  4. D.static token identifying and authenticating a calling application to an API

Answer + AI explanation with Pro

20. Which term means: "binding client JSON to internal fields the caller should not be able to set"?

Mid
  1. A.Mass assignment (API)
  2. B.Rate limiting
  3. C.API key
  4. D.BOLA

Answer + AI explanation with Pro

21. Which statement is correct?

Mid
  1. A.Mass assignment (API) — an API returning more fields than the client needs, leaking sensitive data
  2. B.Mass assignment (API) — capping how many requests a client may make in a window to curb abuse and brute force
  3. C.Mass assignment (API) — entry point that centralizes auth, rate limiting, and routing for backend APIs
  4. D.Mass assignment (API) — binding client JSON to internal fields the caller should not be able to set

Answer + AI explanation with Pro

22. What is GraphQL introspection abuse?

Mid
  1. A.entry point that centralizes auth, rate limiting, and routing for backend APIs
  2. B.querying the GraphQL schema to map and probe an API's full attack surface
  3. C.signing API requests with a shared secret so the server can verify integrity and origin
  4. D.binding client JSON to internal fields the caller should not be able to set

Answer + AI explanation with Pro

23. Which term means: "querying the GraphQL schema to map and probe an API's full attack surface"?

Mid
  1. A.GraphQL query depth limiting
  2. B.API gateway
  3. C.Request signing (HMAC)
  4. D.GraphQL introspection abuse

Answer + AI explanation with Pro

24. Which statement is correct?

Mid
  1. A.GraphQL introspection abuse — Broken Function Level Authorization where a user invokes privileged operations they should not access
  2. B.GraphQL introspection abuse — validating an HMAC signature on inbound webhooks to confirm they came from the real sender
  3. C.GraphQL introspection abuse — an API returning more fields than the client needs, leaking sensitive data
  4. D.GraphQL introspection abuse — querying the GraphQL schema to map and probe an API's full attack surface

Answer + AI explanation with Pro

25. What is BFLA?

Senior
  1. A.an API returning more fields than the client needs, leaking sensitive data
  2. B.static token identifying and authenticating a calling application to an API
  3. C.rejecting API requests whose body or parameters do not match an expected schema
  4. D.Broken Function Level Authorization where a user invokes privileged operations they should not access

Answer + AI explanation with Pro

26. Which term means: "Broken Function Level Authorization where a user invokes privileged operations they should not access"?

Senior
  1. A.API key
  2. B.Request signing (HMAC)
  3. C.BFLA
  4. D.Mass assignment (API)

Answer + AI explanation with Pro

27. Which statement is correct?

Senior
  1. A.BFLA — Broken Function Level Authorization where a user invokes privileged operations they should not access
  2. B.BFLA — an API returning more fields than the client needs, leaking sensitive data
  3. C.BFLA — static token identifying and authenticating a calling application to an API
  4. D.BFLA — capping nested query depth to prevent resource-exhaustion denial of service

Answer + AI explanation with Pro

28. What is GraphQL query depth limiting?

Senior
  1. A.Broken Function Level Authorization where a user invokes privileged operations they should not access
  2. B.entry point that centralizes auth, rate limiting, and routing for backend APIs
  3. C.capping nested query depth to prevent resource-exhaustion denial of service
  4. D.signing API requests with a shared secret so the server can verify integrity and origin

Answer + AI explanation with Pro

29. Which term means: "capping nested query depth to prevent resource-exhaustion denial of service"?

Senior
  1. A.Webhook signature verification
  2. B.BOLA
  3. C.GraphQL query depth limiting
  4. D.BFLA

Answer + AI explanation with Pro

30. Which statement is correct?

Senior
  1. A.GraphQL query depth limiting — Broken Function Level Authorization where a user invokes privileged operations they should not access
  2. B.GraphQL query depth limiting — capping nested query depth to prevent resource-exhaustion denial of service
  3. C.GraphQL query depth limiting — rejecting API requests whose body or parameters do not match an expected schema
  4. D.GraphQL query depth limiting — querying the GraphQL schema to map and probe an API's full attack surface

Answer + AI explanation with Pro

Showing 30 of 36 API Security questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every API Security question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers