Courseiva
mediumMultiple Select

200-901 Practice Question: Implementing an API gateway for its microservices

A company is implementing an API gateway for its microservices. Which TWO security features should be enabled at the gateway to protect backend services?

⚠ Common exam trap

Cisco often tests the distinction between security features that protect the API layer (JWT validation, rate limiting) versus network-level or backend-specific features (DPI, connection pooling), leading candidates to confuse operational optimizations with security controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

JWT validation.

JWT validation (C) is correct because the API gateway should authenticate and authorize requests by verifying the signature, issuer, audience, and expiry of JSON Web Tokens before forwarding traffic to backend microservices, offloading this concern from each service. Rate limiting (E) is correct because throttling requests per client, API key, or IP at the gateway mitigates abuse, brute-force attempts, and denial-of-service traffic before it reaches backend services. In-depth packet inspection (A) is a network-layer/IDS-IPS function, not a typical API gateway security feature, and is unnecessary here. Database connection pooling (B) is a performance/scalability concern, not a security control, and gateways do not manage backend database connections. CORS configuration (D) is a browser-origin policy mechanism for controlling cross-origin requests; while often configured at a gateway, it is not primarily a backend-protection security feature for microservice APIs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    In-depth packet inspection.

    Why it's wrong here

    In-depth packet inspection operates at OSI Layer 7 to analyse payload content, but the question asks for security features at the API gateway, which typically enforces authentication, rate limiting, or token validation—not deep payload analysis. It is tempting because packet inspection can detect malicious payloads in a web application firewall context, where it would be correct for blocking SQL injection or XSS at the network perimeter.

  • ✗

    Database connection pooling.

    Why it's wrong here

    Connection pooling manages reuse of database sockets for application performance and scalability; it enforces no authentication, authorisation or threat filtering at the gateway edge. Pooling belongs in the backend service or data-access layer, and would be selected if the requirement concerned database throughput rather than protecting services.

  • ✓

    JWT validation.

    Why this is correct

    JWT validation at the gateway verifies token signature, issuer, audience and expiry before forwarding requests, so unauthenticated or tampered calls never reach backend microservices. This satisfies the stem's requirement to enable security features at the gateway that protect backend services.

  • ✗

    CORS configuration.

    Why it's wrong here

    CORS governs which browser origins may read responses; it is a client-side browser enforcement mechanism, not protection for backend services against direct API calls. Attackers bypass CORS entirely using non-browser clients. CORS is correct when the requirement is controlling cross-origin web requests, not shielding upstream services.

  • ✓

    Rate limiting.

    Why this is correct

    Rate limiting at the gateway throttles requests per client or API key, absorbing brute-force and denial-of-service floods before they reach backend microservices. This satisfies the stem's requirement to enable security features at the gateway that protect backend services.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.