<< Prev Question Next Question >>

Question 3/18

A FortiWeb administrator sees the following request:
GET /api/v1/data HTTP/1.1
Host: example.com
Authorization: ApiKey abc123def456
The API key belongs to a user in group B who is authorized to access only /api/v1/reports.
What should the administrator do to prevent this unauthorized access?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *