ExamGecko
Question list
Search
Search

Related questions











Question 881 - CISA discussion

Report
Export

An IS auditor discovers that a developer has used the same key to grant access to multiple applications making calls to an application programming interface (API). Which of the following is the BEST recommendation to address this situation?

A.
Replace the API key with time-limited tokens that grant least privilege access.
Answers
A.
Replace the API key with time-limited tokens that grant least privilege access.
B.
Authorize the API key to allow read-only access by all applications.
Answers
B.
Authorize the API key to allow read-only access by all applications.
C.
Implement a process to expire the API key after a previously agreed-upon period of time.
Answers
C.
Implement a process to expire the API key after a previously agreed-upon period of time.
D.
Coordinate an API key rotation exercise with all impacted application owners.
Answers
D.
Coordinate an API key rotation exercise with all impacted application owners.
Suggested answer: A
asked 18/09/2024
Alysson Rodrigo Freires Neto
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first