Search Header Logo

Web Pentest

Authored by Arshaad Mohiadeen

Instructional Technology

University

Used 3+ times

Web Pentest
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

11 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 5 pts

The most effective way of protecting against SQL injection is…

blacklisting strings such as "1 OR 1=1" and "UNION" from input

using an intrusion detection system to detect attacks

white listing input (e.g. only allowing alphanumerical characters and spaces)

use of prepared statements or parametrized queries

2.

MULTIPLE CHOICE QUESTION

30 sec • 5 pts

A cookie can not be used to control a users session/state

False. Cookies are often used for tracking sessions

True, only supercookies have this feature

3.

MULTIPLE CHOICE QUESTION

30 sec • 5 pts

What is IDOR?

Insecure Door or Room

Invalid Data or Reference

Insecure Direct Object Reference

4.

MULTIPLE CHOICE QUESTION

30 sec • 5 pts

What is SQL injection?

It is used to spoof or inject false headers in a HTTP request

It is used in Buffer Overflow attacks to overwrite memory

It is used to inject malicious code to a database server, through a query

5.

MULTIPLE CHOICE QUESTION

30 sec • 5 pts

What is the best practice in defending against SQL injection?

Blocking specific ports that SQL injections are usually attacked via

Programmers will not make web applications that allow user input

Sanitizing users input in a web application

6.

MULTIPLE CHOICE QUESTION

30 sec • 5 pts

Netsparker and Burp Suite Professional are examples of:

Web-focused vulnerability detection tools

VPNs

Web application firewalls

Antimalware

7.

MULTIPLE CHOICE QUESTION

30 sec • 5 pts

Which of the following is not an example of an XSS attack?

Stored XSS

DOM-based XSS

Reflected XSS

DNS XSS

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?