▸case-01 We are configuring rate limiting for an image processing endpoint where traffic averages 1 request per second but users occasionally send bursts of up to 10 requests at once. A developer suggests using a fixed window of 10 seconds with max=10, but this causes window-boundary burst issues. How should the rate limiter be configured using the token bucket pattern to allow 10-request bursts while maintaining a 1 request/second sustained rate? | pass→pass | 15,068 | 19,715 | +31% | 1 | 1 | 0% | 1,886 | 3,102 | +64% | 0 | 0 | — |
▸case-02 In Nginx limit_req module, the default HTTP status code returned when a request is throttled is HTTP 503 Service Unavailable. To conform to standard API rate limiting conventions where clients expect a 4xx client error, which directive sets the throttling response status code to 429? | pass→pass | 8,379 | 10,725 | +28% | 1 | 1 | 0% | 525 | 1,188 | +126% | 0 | 0 | — |
▸case-03 When an API returns an HTTP 429 response, clients need to know how long to pause before re-attempting requests. A team member suggests returning a custom JSON field {"wait_time": 30} in the body. Which standard HTTP response header should be set to convey the wait time in seconds? | pass→pass | 9,188 | 12,096 | +32% | 1 | 1 | 0% | 662 | 1,632 | +147% | 0 | 0 | — |
▸case-04 When implementing IETF draft-ietf-httpapi-ratelimit-headers in API responses, developers want to advertise the maximum request quota allowed in the active time window. A teammate suggests using the legacy X-Rate-Limit-Limit header. Which standardized IETF header field name replaces this legacy header? | pass→pass | 11,113 | 13,641 | +23% | 1 | 1 | 0% | 1,055 | 1,820 | +73% | 0 | 0 | — |
▸case-05 In the IETF draft HTTP rate limiting header specification (draft-ietf-httpapi-ratelimit-headers), which header field explicitly communicates the number of remaining quota units in the current window? | pass→pass | 9,863 | 9,555 | -3% | 1 | 1 | 0% | 864 | 1,174 | +36% | 0 | 0 | — |
▸case-06 We need to implement a precise sliding window rate limiter in Redis across multiple API nodes. A developer suggests using INCR with EXPIRE, but this only supports fixed time windows. Which Redis command is used to add incoming request timestamps as scores to a sorted set for sliding window tracking? | pass→pass | 10,627 | 13,538 | +27% | 1 | 1 | 0% | 970 | 1,988 | +105% | 0 | 0 | — |
▸case-07 We are configuring rate limiting in a multi-pod Node.js Express service. Using default in-memory storage causes each container instance to track quotas separately, allowing clients to bypass limits by hitting different pods. Which store adapter should be passed to the store option of express-rate-limit to centralize state in Redis? | pass→pass | 14,349 | 14,471 | +1% | 1 | 1 | 0% | 1,612 | 1,902 | +18% | 0 | 0 | — |
▸case-08 In Nginx limit_req_zone configuration, developers often set $remote_addr as the key. However, storing string representation of IP addresses consumes 32 to 64 bytes per state entry in shared memory. Which Nginx variable should be used as the zone key to reduce key size to 4 bytes for IPv4 (or 16 bytes for IPv6)? | pass→pass | 10,312 | 13,012 | +26% | 1 | 1 | 0% | 984 | 1,746 | +77% | 0 | 0 | — |
▸case-09 In Nginx limit_req directive, setting burst=10 delays excess requests by queuing and processing them at the steady-state rate, adding latency to client responses. Which parameter must be appended to the limit_req directive to process burst requests immediately without adding delay? | pass→pass | 9,382 | 9,685 | +3% | 1 | 1 | 0% | 637 | 1,010 | +59% | 0 | 0 | — |
▸case-10 In a distributed rate limiter using Redis, running separate GET, INCR, and EXPIRE commands from application code creates race conditions under high concurrent load. Which Redis command executes atomic rate-limiting logic server-side in a single round trip? | pass→pass | 15,754 | 15,797 | +0% | 1 | 1 | 0% | 1,841 | 2,000 | +9% | 0 | 0 | — |
▸case-11 We are setting up API rate limiting middleware for a SaaS platform. A developer proposes keying all requests strictly by incoming client IP address. Why is IP-only keying problematic for authenticated API subscribers behind corporate NATs, and what identifier should be used as the primary cache key for authenticated traffic? | pass→pass | 15,841 | 55,347 | +249% | 1 | 1 | 0% | 2,333 | 3,329 | +43% | 0 | 0 | — |
▸case-12 When configuring throttling limits on an AWS API Gateway Usage Plan, two numeric properties control request limits: steady-state request rate and burst limit. Which property defines the target average steady-state requests per second? | fail→pass | 8,380 | 10,759 | +28% | 1 | 1 | 0% | 488 | 1,232 | +152% | 0 | 0 | — |
▸case-13 An API gateway communicates with a legacy backend database that crashes under sudden concurrent bursts, even if the total request count over a minute is within limits. Which rate limiting algorithm enforces a strict, smooth egress output rate regardless of ingress burstiness? | pass→pass | 11,975 | 13,484 | +13% | 1 | 1 | 0% | 1,072 | 1,602 | +49% | 0 | 0 | — |
▸case-14 We are adding rate limiting to a Python FastAPI service. A team member suggests writing custom middleware that manually checks Redis on every request. Which Python rate-limiting library provides the @limiter.limit() decorator and Limiter extension specifically designed for FastAPI and Starlette applications? | pass→pass | 10,085 | 14,190 | +41% | 1 | 1 | 0% | 900 | 1,953 | +117% | 0 | 0 | — |
▸case-15 AWS Application Load Balancer health checks to /healthz are being blocked with HTTP 429 status by express-rate-limit middleware. A developer suggests raising the global rate limit for all endpoints. What option property in express-rate-limit should be configured to skip rate limiting for health check paths? | pass→pass | 10,060 | 10,598 | +5% | 1 | 1 | 0% | 875 | 1,310 | +50% | 0 | 0 | — |
▸case-16 In a Java Spring Boot microservice using Resilience4j RateLimiter, we want to configure permission refresh intervals. Which configuration property explicitly sets the period of time during which permissions are refreshed? | pass→pass | 9,210 | 9,781 | +6% | 1 | 1 | 0% | 730 | 1,195 | +64% | 0 | 0 | — |
▸case-17 We need to track rate limits for millions of active users in Redis. Sliding Window Log using Redis Sorted Sets consumes O(N) memory per request, while Fixed Window suffers from boundary spikes. Which hybrid algorithm provides O(1) memory complexity using weighted request counts from the previous and current window? | pass→pass | 17,482 | 21,515 | +23% | 1 | 1 | 0% | 2,206 | 3,453 | +57% | 0 | 0 | — |
▸case-18 In a .NET 8 Web API, a developer proposes installing an unmaintained third-party NuGet package for rate limiting. What native framework namespace included in .NET 7+ provides built-in rate limiting middleware without third-party dependencies? | pass→pass | 9,876 | 15,344 | +55% | 1 | 1 | 0% | 844 | 2,241 | +166% | 0 | 0 | — |
▸case-19 When configuring Cloudflare Rate Limiting rules for an API endpoint, applying the default action presents an interactive CAPTCHA challenge that breaks automated API clients. Which action setting should be configured to block excess requests and return an HTTP 429 response? | pass→pass | 10,108 | 15,576 | +54% | 1 | 1 | 0% | 744 | 2,126 | +186% | 0 | 0 | — |
▸case-20 In a multi-node Kong Gateway cluster, deploying the rate-limiting plugin with default settings stores counter states locally in node memory, causing nodes to enforce quotas independently. Which policy setting in config.policy guarantees global cluster-wide quota enforcement? | pass→pass | 7,110 | 16,019 | +125% | 1 | 1 | 0% | 1,190 | 1,937 | +63% | 0 | 0 | — |
▸case-21 Single-page application frontend clients cannot read the RateLimit-Remaining response header returned by a cross-origin API server due to browser security restrictions. Which CORS response header must the API server configure to allow browser JavaScript to access rate limiting headers? | pass→pass | 3,725 | 10,597 | +184% | 1 | 1 | 0% | 641 | 1,309 | +104% | 0 | 0 | — |
▸case-22 Our microservice team wants to prevent cascading failures when an external third-party payment gateway experiences outages or high latency. A developer proposes adding an aggressive rate limiter on our outbound calls to the payment gateway. Why is rate limiting insufficient for downstream failure isolation, and which resilience pattern should be implemented instead? | pass→pass | 16,571 | 18,400 | +11% | 1 | 1 | 0% | 2,483 | 3,665 | +48% | 0 | 0 | — |
▸case-23 We need to validate that incoming POST request payloads strictly conform to our JSON schema definitions before reaching our Express route handlers. A junior developer suggests using rate limiting middleware to validate request body fields. How should JSON schema validation be implemented in Express? | pass→pass | 16,100 | 15,256 | -5% | 1 | 1 | 0% | 2,745 | 3,427 | +25% | 0 | 0 | — |
▸case-24 How should an API authentication service configure RS256 asymmetric token signing for OAuth2 JWT access tokens using public and private key pairs in Node.js? | fail→fail | 16,662 | 20,352 | +22% | 1 | 1 | 0% | 3,362 | 4,014 | +19% | 0 | 0 | — |