Search Header Logo

Broken Access control II

Authored by G3C Team

Other

Professional Development

Used 28+ times

Broken Access control II
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

10 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

20 sec • 1 pt

Vulnerabilities associated with Broken Access Control:

[Multiple Choice]

Forced Browsing

IDOR

LFI

All of the above

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

$file = $_GET['file'];

include('directory/' . $file);


This PHP code can lead to:

XXE

Local File Inclusion

Insecure Direct Object Reference

Cross-site scripting

3.

MULTIPLE SELECT QUESTION

30 sec • 1 pt

The secure file permission(s) are:

-rws---r-x root root

-rwx------ root root

drwxr-x-w- root root

-r-xr-xr-x root root

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Forced Browsing is:

Forcing the application to upload malicious file

Remote code execution in the webserver

enumerate and access resources that are not referenced by the application, but are still accessible

None of these

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What threat are you vulnerable to if you do not validate authorization of user for direct references to restricted resources?

Cross site scripting

Cross Site Request Forgery

SQL Injection

Insecure Direct Object References

6.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

Which of the following are effective ways to implement access control?

[Multiple Choice]

Implementing Access Control Matrix for application resources

Using hidden form fields to authorize

Logging unauthorized users actions

Enforcing RWX permission for every files on server for everyone

7.

MULTIPLE CHOICE QUESTION

20 sec • 1 pt

Taking control of Admin functionality and Misusing sensitive data that they are unauthorized to access is:

Xml Enternal Entities Injection

SQL Injection

Cross site scripting

Broken Access Control

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?