Question 226
Application sometimes store configuration as constants in the code, which is a violation of strict separation of configuration from code. Where should application configuration be stored?
Question 227
Which type of file is created from issued intermediate, root, and primary certificates for SSL installation on a server?
Question 228
Which two techniques protect against injection attacks? (Choose two.)
Question 229
Drag and drop the descriptions from the left onto the related OAuth-defined roles on the right.


Question 230
Which two methods are API security best practices? (Choose two.)

