問題文
A policy such as authentication or rate limiting is needed on an API. It could be hand-coded inside the application or applied as a managed policy at the gateway. Which reasoning favors the managed policy?
選択肢
- A managed policy requires editing and redeploying the source code every time the rule changes, so it offers no advantage at all.
- Hand-coding the rule in each application is always easier to maintain than a managed policy, because duplicating the same logic in every app keeps it consistent by itself.
- Applying it as a managed policy keeps the rule out of the code, so it can be changed and reused consistently without redeploying every application that needs it.
- Where a policy is applied has no effect on maintainability or reuse, so hand-coding it in each app is equally good.