Review cards · 17 cards

Security

Authentication and authorization, tokens and cookies, TLS between services, secrets, encryption and abuse.

Train security in daily review

Cards

  1. Checking who is calling is _____; checking what that caller is allowed to do is _____. easy Fill in the blank
  2. Anyone holding a signed JWT can read its claims: the payload is only _____-encoded, not encrypted. The signature proves the claims were not _____. easy Fill in the blank
  3. A thumbnail worker reads uploaded images and writes thumbnails to the same bucket. Which permissions follow least privilege? easy Multiple choice
  4. Why is an app that authenticates with a session cookie exposed to CSRF, while one that sends a bearer token in the Authorization header is not? medium Multiple choice
  5. The cloud database encrypts its disks at rest with a managed key. Which attack does that stop? medium Multiple choice
  6. Private files are shared through signed download URLs. A link gets posted publicly. What limits the damage best? medium Multiple choice
  7. Logins are limited to 5 attempts a minute per account. How long would one attacker need to try 1 million passwords against a single account? medium Estimate
  8. What does mutual TLS between internal services add over ordinary TLS, and what does it cost? medium Flashcard
  9. Why does a mobile app or single-page app use the OAuth authorization code flow with PKCE? medium Flashcard
  10. How should a service get its database password, and how do you rotate it without downtime? medium Flashcard
  11. Where should a browser app keep its session token, and with which cookie flags? medium Flashcard
  12. A login endpoint limits each IP address to 10 attempts a minute. A botnet with 10,000 IP addresses runs a credential-stuffing attack. How many attempts an hour can it make? hard Estimate
  13. What is envelope encryption with a KMS, and why not send all the data to the KMS to encrypt? hard Flashcard
  14. An API already requires idempotency keys. Does that protect it against an attacker replaying a captured request? hard Flashcard
  15. A service receives a JWT whose header says "alg": "none". What should it do? hard Multiple choice
  16. A user logs out or is banned, but their JWT access token is still valid for an hour. Why can't you just revoke it, and what are the options? hard Flashcard
  17. A "link preview" feature makes the server fetch any URL a user pastes. What is the main risk? hard Multiple choice

More topics