nerdexam
Isaca

CDPSE · Question #130

Which of the following is the GREATEST privacy risk associated with the use of application programming interfaces (APIs)?

The correct answer is B. API keys could be stored insecurely. API keys act as credentials that authenticate and authorize access to data and services exposed through an API, which often includes personal data. If API keys are stored insecurely-such as hardcoded in source code, committed to public repositories, stored in plain-text…

Privacy Architecture

Question

Which of the following is the GREATEST privacy risk associated with the use of application programming interfaces (APIs)?

Options

  • AAPIs are costly to assess and monitor.
  • BAPI keys could be stored insecurely.
  • CAPIs are complex to build and test
  • DAPIS could create an unstable environment

How the community answered

(31 responses)
  • A
    16% (5)
  • B
    71% (22)
  • C
    10% (3)
  • D
    3% (1)

Explanation

API keys act as credentials that authenticate and authorize access to data and services exposed through an API, which often includes personal data. If API keys are stored insecurely-such as hardcoded in source code, committed to public repositories, stored in plain-text configuration files, or logged in cleartext-they can be discovered by unauthorized parties. An attacker with a valid API key can impersonate the legitimate application and access, extract, or manipulate personal data at scale, creating a direct and serious privacy breach. The other options describe operational or technical challenges (cost, complexity, stability) but are not inherently privacy risks.

Topics

#API Security#Privacy Risk Management#Authentication#Access Control

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice