Which three measures should be implemented to secure a RESTful API? (Select THREE.)
Generic error messages prevent information leakage.
Why this answer
Proper error handling in a RESTful API must never expose stack traces or internal implementation details to the client. Stack traces can reveal file paths, database schemas, library versions, and logic flows that attackers can exploit to craft targeted attacks. Instead, the API should return generic error messages (e.g., '500 Internal Server Error') while logging full details server-side for debugging.
Exam trap
CASP+ often tests the misconception that disabling rate limiting improves availability, when in fact it destroys availability by removing protection against resource exhaustion attacks.