Slide 27 of 28
Part 4 · QuizSlide 27
Slide 27 · Quiz
Five questions. No pressure.
Test what you understood — not what you memorized.
QUESTION 01 OF 05
You're logged into a shopping app. Your order is at /api/orders/5021. You change the URL to /api/orders/5020 and see a different customer's order. What type of vulnerability is this?
QUESTION 02 OF 05
What is the core difference between authentication and authorization?
QUESTION 03 OF 05
The Peloton breach exposed 4 million users' private data. What made it especially easy to exploit?
QUESTION 04 OF 05
When an API denies access to an object a user doesn't own, which HTTP status code should it return — and why?
QUESTION 05 OF 05
T-Mobile's 2023 breach exposed 37 million customer records over 6 weeks undetected. Which mitigation would have been most likely to catch it early?
← Back Done → See what you learned →