Google Professional Cloud Developer exam dumps

Google Professional Cloud Developer practice question 360 of 481

Professional Cloud Developer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Developer Question 360

Select 3Google Cloud Platform

You are developing an API for an e-commerce platform that will be exposed to third-party developers. To ensure security and scalability, you decide to use Apigee as the API management platform. Which of the following actions should you take to secure the API while allowing controlled access to third-party developers?

  1. A

    Implement API key validation for all incoming requests.

  2. B

    Use Apigee's OAuth 2.0 policies to enable token-based authentication.

  3. C

    Allow unrestricted access to the API to improve performance for third-party developers.

  4. D

    Enable rate limiting and quota policies in Apigee to prevent abuse.

  5. E

    Store sensitive information, such as API keys and credentials, in the API's configuration files.

Show answer and explanation

Correct answers: A, B, D

Explanation

To secure an API exposed to third-party developers, it is important to implement authentication and authorization mechanisms, such as API key validation and OAuth 2.0. Additionally, rate limiting and quota policies in Apigee ensure controlled and fair access while preventing abuse. Avoid practices like storing sensitive data in configuration files or allowing unrestricted access, as these can compromise the security and reliability of the API.

  • A. Correct.

    Correct: API key validation ensures that only authorized clients can access the API, adding a layer of security.

  • B. Correct.

    Correct: Token-based authentication via OAuth 2.0 is a best practice for securing APIs, especially when dealing with third-party developers.

  • C. Incorrect.

    Incorrect: Allowing unrestricted access would compromise the security of the API and expose it to potential abuse.

  • D. Correct.

    Correct: Rate limiting and quota policies help control traffic and prevent overuse or abuse of the API by third-party developers.

  • E. Incorrect.

    Incorrect: Storing sensitive information in configuration files is a security risk and violates best practices. Instead, use a secrets management solution.

Timed practice exam

Take a Google Professional Cloud Developer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam