# セキュリティのベストプラクティス (Node.js / NestJS) > Helmet、CORS、rate limiting、入力のサニタイズ、SQL injection、XSS、CSRF - 25 面接問題 - Senior - [面接問題: Node.js / NestJS](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions.md) ## 1. NestJS の文脈における Helmet とは何ですか? **回答** Helmet は、一般的な脆弱性からアプリケーションを保護するために HTTP セキュリティヘッダーを自動的に設定するミドルウェアです。X-Frame-Options、Content-Security-Policy、X-Content-Type-Options などのヘッダーを有効にし、XSS、clickjacking、MIME sniffing を防ぎます。Helmet は、セキュリティの防御面を強化するための本番環境における必須のベストプラクティスです。 ## 2. API における CORS の主な役割は何ですか? **回答** CORS(Cross-Origin Resource Sharing)は、どの外部ドメインが API リソースにアクセスできるかを制御します。CORS の設定がない場合、ブラウザはセキュリティ上の理由から異なるドメインからのリクエストをブロックします。CORS を適切に設定することで、セキュリティを維持しながらアクセスエラーを防げます。すべてのドメインを wildcard で許可するのではなく、許可するオリジンのホワイトリストを使用しましょう。 ## 3. ブルートフォース攻撃から API を保護するための最善のアプローチは何ですか? **回答** rate limiting は、一定期間における IP やユーザーごとのリクエスト数を制限し、自動化されたブルートフォース攻撃を防ぎます。NestJS の throttler-module のようなパッケージを使えば、グローバルまたはエンドポイントごとの制限を簡単に設定できます。rate limiting を段階的な戦略(一時的なブロック時間の増加)や、機密性の高いエンドポイント向けの CAPTCHA と組み合わせましょう。rate limiting はサービス拒否(DoS)に対する保護にもなります。 ## さらに22問利用可能 - XSS(Cross-Site Scripting)攻撃とは何ですか? - NestJSアプリケーションをSQLインジェクションから保護するにはどうすればよいですか? 無料で登録: https://sharpskill.dev/ja/login ## その他のNode.js / NestJS面接トピック - [Node.js の基礎](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/nodejs-fundamentals.md): 20問, Junior - [Node.js コア API](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/nodejs-core-apis.md): 25問, Junior - [非同期プログラミング](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/asynchronous-programming.md): 25問, Junior - [Express.js の基礎](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/express-basics.md): 20問, Junior - [NestJSの基礎](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/nestjs-fundamentals.md): 23問, Junior - [REST API 設計](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/rest-api-design.md): 20問, Junior - [バリデーションとDTO](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/validation-dto.md): 20問, Junior - [APIドキュメントと契約](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/api-documentation.md): 20問, Junior - [エラーハンドリング](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/error-handling.md): 20問, Junior - [ユニットテスト](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/testing-unit.md): 20問, Junior - [タスクスケジューリング](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/scheduling-cron.md): 15問, Junior - [NestJS のモジュールと DI](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/nestjs-modules-di.md): 20問, Mid-Level - [設定と環境管理](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/configuration-environment.md): 20問, Mid-Level - [JWT認証](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/authentication-jwt.md): 25問, Mid-Level - [認可とRBAC](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/authorization-rbac.md): 20問, Mid-Level - [TypeORMによるデータベース](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/database-typeorm.md): 30問, Mid-Level - [Prisma ORM](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/prisma-orm.md): 25問, Mid-Level - [ミドルウェアとインターセプター](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/middleware-interceptors.md): 20問, Mid-Level - [ファイルアップロード](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/file-upload.md): 15問, Mid-Level - [WebSockets](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/websockets.md): 20問, Mid-Level - [NestJSによるGraphQL](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/graphql-basics.md): 25問, Mid-Level - [エンドツーエンドテスト](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/testing-e2e.md): 20問, Mid-Level - [Redisによるキャッシング](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/caching-redis.md): 20問, Mid-Level - [Bull によるキュー](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/queues-bull.md): 20問, Mid-Level - [DevOps、Logging、CI/CD](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/logging-monitoring.md): 25問, Mid-Level - [Docker とコンテナ化](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/docker-containerization.md): 25問, Mid-Level - [マイクロサービス](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/microservices.md): 30問, Senior - [パフォーマンスとクラウドデプロイ](https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/performance-optimization.md): 30問, Senior --- Source: SharpSkill (https://sharpskill.dev), tech interview preparation for your real stack. HTML version of this page: https://sharpskill.dev/ja/technologies/node-nestjs/interview-questions/security-best-practices