Lesson 5 of 5 15 min +150 XP
🧠 Webhook Assessment
Answer all questions to complete the quiz and earn 150 XP.
1
Your webhook handler takes 45 seconds to process. Stripe times out after 30 seconds and retries. What should you change?
2
A user reports receiving the same webhook event three times. Your logs show three successful deliveries. What's likely happening?
3
You're building a webhook sender. A customer's endpoint returns 503 (Service Unavailable). What should you do?
4
Your webhook receiver parses JSON before verifying the signature. Why is this a security risk?
5
A webhook event has timestamp 1699999999, but your server time is 1700000500 (501 seconds later). Should you accept it?
6
Your e-commerce platform needs to notify customers about order updates. Which events should you expose as webhooks?
7
You receive an 'invoice.payment_failed' webhook, but 'invoice.paid' arrives 2 seconds later (out of order). How should you handle this?
8
Your webhook endpoint has been discovered by an attacker sending fake events. What's your first line of defense?
9
A webhook delivery failed after 5 retry attempts over 72 hours. What should happen to this event?
10
Your webhook handler stores event IDs in Redis with a 7-day TTL for idempotency. Why use a TTL instead of storing forever?
11
You're implementing webhook signatures. Should you include the timestamp in the signed payload?
12
Your webhook receiver needs to call an external API that takes 10+ seconds. How should you architect this?
13
A customer wants to receive webhooks but their firewall blocks incoming requests. What alternative can you offer?
14
When should your webhook sender disable a customer's endpoint automatically?
15
Your webhook system sends 1 million events per day. How should you handle customers who want to receive only specific event types?
correct