Bookmark this page

Quiz: Securing APIs with Red Hat 3scale API Management

    Choose the correct answers to the following questions:

  1. 1.

    Which one of the following statements about authentication in Red Hat 3scale API Management is correct?

    A

    APIs that are managed by 3scale API Management must use an adapter library to integrate with the authentication workflow.

    B

    3scale API Management does not support any cryptographically verified authentication method.

    C

    You can require authentication for APIs that are managed by 3scale API Management without the need to redeploy or modify your API.

    D

    3scale API Management only supports authentication concerns when you integrate it with Red Hat Single Sign On.

  2. 2.

    When you try to access a web application that communicates with an API managed by 3scale API Manager, you are presented with the following CORS error. Which one of the provided statements is the most likely cause and solution for the error?

    Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at https://example-product-3scale-apicast-staging.apps.ocp4.example.com/
    A

    You must modify your API to include a proper CORS header value in the API response.

    B

    You can use the CORS Request Handling policy. This means APIcast will include a proper CORS header value in the API response.

    C

    You must adapt your front end application to include a proper header in the request.

    D

    3scale API Management does not support interactions by using a browser.

  3. 3.

    Consider that you configured 3scale Application Management to integrate with Red Hat Single Sign On (RHSSO). Which one of the following statements about account object synchronization is correct?

    A

    3scale Application Management migrates all application objects to RHSSO. After the migration, 3scale Application Management deletes all local application objects and defers to RHSSO.

    B

    You must recreate all application objects in RHSSO manually. You can keep the application objects in 3scale Application Management for reference.

    C

    3scale Application Management does not support integration with RHSSO.

    D

    The Zync component synchronizes any application objects associated with the product that is configured to integrate with RHSSO.

  4. 4.

    Which one of the following statements about regenerating API keys in 3scale Application Management is correct?

    A

    You can generate up to five API keys when you use the key-ID authentication pattern.

    B

    The only way to regenerate an API key is to create a new application object.

    C

    You can generate up to five API keys when you use the API key authentication pattern.

    D

    You must regenerate your API keys periodically.

Revision: do240-2.11-40390f6