An API validates the caller's token on every request but performs no ownership check on the object requested. Which weakness is present?
CCNP Security SDSI
CISCO_SDSI_300_745Ready to test yourself?
A timed, blueprint-proportional exam drawn fresh from this bank โ with a per-domain score report.
๐ Free preview: showing 10 of 200 questions. Unlock the full bank โ every question, explanation, and reference.
Unlock all 200 questions โ10 questions across 4 topics. Choose an answer for each question, then check it to see the correct answer and explanation.
Filter by topic
All 10 questions
Applications
10 questions in topicSelecting controls from application data classification and traffic flows, securing cloud-native applications, microservices, containers and microsegmentation, API and workload identity design, and the impact of generative AI and quantum computing on application security policy.
Which practice ensures a deployed container image matches the one that was tested?
Which design property makes a post-quantum cryptographic migration feasible?
Which two inputs determine what controls an application warrants?
Which security consequence follows from decomposing a monolith into many microservices?
Which control prevents a compromised microservice from freely invoking its peers?
Which capability does a service mesh move out of individual application code?
Which control observes behavior a container image scan cannot predict?
Which customer responsibility remains under a managed Kubernetes service?
Which prerequisite makes a microsegmentation policy safe to enforce?