Certified API Pentester (C-APIPen) 試験
最新更新時間: 2026/09/21
【秋学習応援セール|10月限定キャンペーン】:C-APIPen 最新真題を買う時、日本語版と英語版両方を同時に獲得できます。
実際の問題集を練習し、試験のポイントを了解し、テストに申し込むするかどうかを決めることができます。
さらに試験準備時間の35%を節約するには、C-APIPen 問題集を使用してください。
Question No : 1
A reset link contains a base64-encoded token. Describe how to assess whether it's reversible or discloses user data.
正解:
Explanation:
Question No : 2
You identify that a reset token is stored client-side in a cookie.
How would you test for insecure storage or manipulation?
正解:
Explanation:
Question No : 3
How do you test if reset tokens are valid beyond their expected expiration period?
正解:
Explanation:
Question No : 4
You observe that reset tokens are sent as links with predictable values.
How would you test the reset token for predictability?
正解:
Explanation:
Question No : 5
The password reset form allows unauthenticated users to request a reset token by entering their email.
How do you test it for user enumeration?
正解:
Explanation:
Question No : 6
You find a GraphQL mutation login(email, password) that returns null on failure.
How do you test it for brute force vulnerability?
正解:
Explanation:
Question No : 7
An API endpoint is rate-limited but doesn't blacklist IPs.
How would you bypass brute-force protection using distributed spraying?
正解:
Explanation:
Question No : 8
How do you test for password spraying against an API that supports HTTP Basic Authentication?
正解:
Explanation:
Question No : 9
A login API returns “Invalid username or password” on failed login.
How would you detect user enumeration via brute force?
正解:
Explanation:
Question No : 10
You identify a login endpoint at /api/login accepting JSON credentials. Describe how to test it for a basic brute-force attack.
正解:
Explanation:
Question No : 11
You find a custom shell wrapper API where the endpoint executes a CLI tool with user input.
How can you safely and effectively test this for injection?
正解:
Explanation:
Question No : 12
A request uses Referer or User-Agent for logging.
How would you check these headers for command injection vulnerabilities?
正解:
Explanation:
Question No : 13
You encounter an API for generating dynamic PDFs using LaTeX.
How would you exploit this for command injection?
正解:
Explanation:
Question No : 14
You’re testing a server-side rendered analytics dashboard that accepts a filter input.
How would you confirm template or code injection?
正解:
Explanation:
Question No : 15
A login form uses HTTP Basic Auth.
How can you test it for SQL Injection if you cannot directly modify the query?
正解:
Explanation: