nerdexam
Isaca

CISA · Question #568

An organization has recently implemented additional application programming interfaces (APIs) to enhance data exchange with vendors. Which of the following is MOST important to ensure coverage of API-

The correct answer is C. Testing the authorization mechanisms in place to secure API endpoints. Authorization controls are critical in API security because they ensure that only authenticated and properly authorized users or systems can access specific data or functions. Weak or missing authorization can lead to data breaches or unauthorized data manipulation, making this t

Submitted by priya_blr· Apr 18, 2026Protection of Information Assets

Question

An organization has recently implemented additional application programming interfaces (APIs) to enhance data exchange with vendors. Which of the following is MOST important to ensure coverage of API-related risks during the next API management process audit?

Options

  • AEvaluating the compliance of APIs with the organization's standards and best practices
  • BVerifying the adequacy of disaster recovery and business continuity plans for critical APIs
  • CTesting the authorization mechanisms in place to secure API endpoints
  • DReviewing the process of API documentation and version control to ensure accuracy and

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    75% (27)
  • D
    17% (6)

Explanation

Authorization controls are critical in API security because they ensure that only authenticated and properly authorized users or systems can access specific data or functions. Weak or missing authorization can lead to data breaches or unauthorized data manipulation, making this the most important focus area for an API management process audit.

Topics

#API Security#Authorization Controls#Information Asset Protection#Audit Testing

Community Discussion

No community discussion yet for this question.

Full CISA Practice