easyMultiple Select
200-901 Practice Question: A developer is building a RESTful API with Python…
A developer is building a RESTful API with Python Flask. Which TWO are recommended security best practices for exposing the API over HTTPS?
⚠ Common exam trap
Cisco often tests the misconception that HTTPS alone makes an API secure, but the trap here is that encryption only protects data in transit, not the application logic—so candidates must remember that input validation and rate limiting are still required server-side defenses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Validate and sanitize all user input.
Option B is correct because validating and sanitizing all user input defends against injection attacks (SQL injection, XSS, command injection) and malformed payloads that could compromise a Flask REST API, and it should be applied to query parameters, path variables, headers, and JSON bodies. Option E is correct because rate limiting (e.g., via Flask-Limiter with limits like 100 requests per minute per IP or API key) mitigates brute-force, credential-stuffing, and denial-of-service abuse against exposed HTTPS endpoints. Option A is not recommended: HTTP Basic Authentication sends base64-encoded credentials that are only protected by TLS and lacks token expiry, MFA, and scoping, so it is considered weak for API security. Option C is wrong because enabling CORS for all origins (Access-Control-Allow-Origin: *) exposes the API to cross-origin data theft and should be restricted to trusted origins. Option D is wrong because storing passwords in plaintext violates fundamental credential-storage practice; passwords must be hashed with a slow algorithm such as bcrypt, scrypt, or Argon2.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use HTTP Basic Authentication for simplicity.
Why it's wrong here
HTTP Basic Authentication transmits base64-encoded credentials on every request, which is not encryption and is replayable over intercepted traffic. It is tempting for quick internal prototypes, but production APIs over HTTPS should use token-based schemes such as OAuth 2.0 or JWT with short expiry.
- ✓
Validate and sanitize all user input.
Why this is correct
Validating and sanitising all user input strips injection payloads such as SQL, command and cross-site scripting content before the Flask API processes requests, preventing malformed or malicious data from reaching backend systems. This satisfies the stem's requirement for a recommended security practise when exposing the API over HTTPS.
- ✗
Enable CORS for all origins.
Why it's wrong here
Enabling CORS for all origins lets any website issue cross-origin requests with the user's credentials, undermining the API's same-origin protections. It is tempting during front-end development, but production should restrict Access-Control-Allow-Origin to specific trusted domains rather than a wildcard.
- ✗
Store passwords in plaintext in the database.
Why it's wrong here
Plaintext password storage exposes every credential if the database is breached, violating basic confidentiality requirements. It is tempting for debugging or legacy compatibility, but passwords must be hashed with a salted algorithm such as bcrypt or Argon2, never stored reversibly.
- ✓
Implement rate limiting to prevent abuse.
Why this is correct
Rate limiting caps the number of requests a client can make within a defined window, mitigating brute-force, credential-stuffing and denial-of-service abuse against the Flask API. This satisfies the stem's requirement for a recommended security practise when exposing the API over HTTPS.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.