Your question is Protect Sensitive API Endpoints. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
You're reviewing a backend service that exposes sensitive API endpoints for account data and administrative actions. Before rollout, you need to make sure the endpoints are protected against common web vulnerabilities and that the team has a practical plan to reduce security risk without blocking delivery.
What security measures would you implement to protect sensitive API endpoints from common vulnerabilities like SQL injection and Cross-Site Scripting (XSS)?