To restrict access to certain resources in RESTful APIs, ___________ is commonly employed.

  • OAuth
  • API keys
  • HTTPS
  • JSON Web Tokens (JWTs)
The correct option is HTTPS. HTTPS (Hypertext Transfer Protocol Secure) is commonly used to secure RESTful API communications by encrypting data exchanged between clients and servers. It helps prevent unauthorized access, data tampering, and eavesdropping. HTTPS is a fundamental security measure in modern web development, including RESTful API implementations.

Which SDLC model is best suited for large projects with uncertain or evolving requirements?

  • Agile
  • RAD
  • Spiral
  • Waterfall
Agile methodologies are best suited for large projects with uncertain or evolving requirements because they emphasize flexibility, collaboration, and iterative development. Unlike Waterfall, Agile allows for continuous feedback, frequent testing, and adaptation to changes, making it ideal for dynamic project environments.

What is the difference between pre-emptive and non-preemptive scheduling of threads?

  • Fixed time allocation, priority inversion handling
  • Thread blocking prevention, dynamic priority adjustment
  • Thread priority management, time-slicing for fairness
  • Time-sharing among threads, priority boosting
Pre-emptive scheduling involves the operating system preempting a thread's execution based on factors such as priority and time-slicing, ensuring fairness and responsiveness in multitasking environments. Thread priority management and time-sharing mechanisms are typical features of pre-emptive scheduling. On the other hand, non-preemptive scheduling allows threads to run until they voluntarily yield or block, without the system forcibly interrupting their execution. It often involves fixed time allocations or priority inversion handling strategies to manage thread execution.

What is the difference between clustered and non-clustered indexes?

  • Clustering key
  • Data duplication
  • Organization of data physically
  • Type of indexing
Clustered indexes dictate how data is physically organized in the database, arranging rows in the order of the clustered index key, while non-clustered indexes store a separate structure pointing to the data rows.

You're working on a project where performance optimization is critical. How would you minimize render-blocking CSS and improve page load speed?

  • Implement server-side rendering for CSS to reduce client-side processing.
  • Inline all CSS styles directly into the HTML document.
  • Minify and concatenate CSS files to reduce the number of HTTP requests.
  • Use JavaScript to load CSS asynchronously after the page content is loaded.
To minimize render-blocking CSS and improve page load speed, techniques like minification and concatenation are effective. Minifying CSS involves removing unnecessary spaces, comments, and reducing file size, which speeds up download times. Concatenation combines multiple CSS files into a single file, reducing HTTP requests. These optimizations help browsers fetch and render CSS more efficiently, leading to faster page load speeds, crucial for performance-critical projects.

Which protocol is primarily used for transferring files over the internet?

  • FTP
  • POP3
  • SMTP
  • TCP
FTP stands for File Transfer Protocol. It is a standard network protocol used for the transfer of computer files between a client and server on a computer network. FTP operates on a client-server model where the user initiates a connection to the server to perform file transfers.

How does denormalization differ from normalization, and when is it appropriate to use?

  • Enhances data integrity
  • Increases redundancy for faster read operations
  • Maintains data consistency
  • Reduces redundancy for efficient storage
Denormalization involves combining tables to reduce joins for faster read operations at the expense of increased redundancy. It is appropriate in read-heavy applications where performance is critical.

Memory ___________ is a technique used to rearrange memory contents to place all free memory together.

  • Allocation
  • Compaction
  • Fragmentation
  • Paging
Memory compaction is a technique used in memory management to reduce fragmentation by rearranging memory contents to place all free memory together in contiguous blocks. This helps in maximizing the available memory for allocating new processes or data structures, especially in systems where memory fragmentation can lead to inefficient memory usage.

Explain the concept of spanning tree protocol (STP) and its role in preventing network loops.

  • STP elects a root bridge to serve as a reference point for path calculations and topology stability.
  • STP operates at Layer 3 of the OSI model and prioritizes traffic based on VLAN configurations.
  • STP uses BPDU messages to exchange information between switches and determine the best path to the root bridge.
  • Spanning Tree Protocol (STP) prevents network loops by blocking redundant paths in a switched network.
STP is vital for ensuring network stability and preventing broadcast storms caused by looping paths in Ethernet networks. By intelligently blocking redundant links while maintaining alternative paths, STP maintains a loop-free topology, optimizing network performance and reliability.

In your role as a security analyst, you discover a vulnerability in a web application that allows attackers to execute arbitrary SQL queries. How would you advise the development team to remediate this vulnerability?

  • Use parameterized queries or prepared statements to sanitize user input and prevent SQL injection attacks.
  • Implement strict input validation on user inputs, perform regular security audits and code reviews.
  • Utilize a web application firewall (WAF) to block malicious SQL queries, restrict database permissions to minimize attack surface.
  • Educate developers on secure coding practices, use stored procedures to encapsulate database operations.
Option 1 suggests using parameterized queries or prepared statements, which are fundamental to preventing SQL injection attacks by separating user input from SQL commands. Option 3 involves additional security measures like WAF and database permissions, which are beneficial but secondary to fixing the core vulnerability. Option 4 addresses secure coding practices but does not focus specifically on remedying SQL injection vulnerabilities.