Basic API Testing questions
1. What is an API and what is REST?
An API is a contract that lets software systems talk to each other. REST is an architectural style using HTTP resources identified by URLs, standard methods, stateless requests and representations such as JSON.
2. Explain the common HTTP methods.
GET reads data, POST creates, PUT replaces a resource, PATCH partially updates and DELETE removes. GET, PUT and DELETE should be idempotent; POST usually is not.
3. Which status codes should every tester know?
200 OK, 201 Created, 204 No Content, 400 Bad Request, 401 Unauthorized, 403 Forbidden, 404 Not Found, 409 Conflict, 422 Unprocessable Entity, 429 Too Many Requests, 500 Internal Server Error and 503 Service Unavailable.
4. 401 vs 403?
401 means the request is not authenticated (missing or invalid credentials). 403 means the caller is authenticated but not allowed to access that resource.
Intermediate API Testing questions
5. What do you validate in an API response?
Status code, response time, headers (content type, caching), the JSON schema, field values and data types, business rules, error messages for invalid input and that data is actually stored correctly in the database.
6. How do you chain requests in Postman?
Extract a value in the Tests script, for example pm.environment.set('token', pm.response.json().token), and reference it as {{token}} in later requests. Collections can then run in order with the Collection Runner or Newman in CI.
7. What authentication types are common?
API keys, Basic auth, Bearer tokens such as JWT, OAuth 2.0 flows (client credentials, authorization code) and session cookies. Test both valid access and rejection of expired, missing or tampered credentials.
8. What negative tests do you run on an API?
Missing required fields, wrong data types, boundary lengths, invalid IDs, duplicate creation, unauthorized and forbidden access, unsupported methods, very large payloads and injection strings, checking for correct 4xx codes and safe error messages.
Advanced API Testing questions
9. How do you automate API tests with Rest Assured?
Use the given().header().body().when().post(url).then().statusCode(201).body('id', notNullValue()) style with TestNG or JUnit, POJOs for serialization, JSON schema validation, and environment configuration for different servers.
10. What is contract testing?
Contract testing (for example with Pact) verifies that a provider API still satisfies the requests and responses its consumers expect, catching breaking changes between microservices without full end-to-end environments.
Want to practise these with a trainer? APEX live batches include mock interviews, real projects and placement support. See upcoming batches.
