Web Pentest

Web Pentest

University

11 Qs

quiz-placeholder

Similar activities

Cloud migration prerequisite

Cloud migration prerequisite

University - Professional Development

15 Qs

Base de Datos I - Parte 4

Base de Datos I - Parte 4

University

10 Qs

Normas APA

Normas APA

University

13 Qs

TERMS OF DATABASE

TERMS OF DATABASE

4th Grade - University

10 Qs

APRENDIENDO SOBRE REDES INDUSTRIALES

APRENDIENDO SOBRE REDES INDUSTRIALES

University

11 Qs

DW-A2

DW-A2

University

10 Qs

Lección2_Eval 2.2_ Manual Fundamentos de bases de datos.

Lección2_Eval 2.2_ Manual Fundamentos de bases de datos.

University

10 Qs

Fundamentos de Bases de datos_ Lección 1.

Fundamentos de Bases de datos_ Lección 1.

University

10 Qs

Web Pentest

Web Pentest

Assessment

Quiz

Instructional Technology

University

Medium

Created by

Arshaad Mohiadeen

Used 3+ times

FREE Resource

11 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 5 pts

The most effective way of protecting against SQL injection is…

blacklisting strings such as "1 OR 1=1" and "UNION" from input

using an intrusion detection system to detect attacks

white listing input (e.g. only allowing alphanumerical characters and spaces)

use of prepared statements or parametrized queries

2.

MULTIPLE CHOICE QUESTION

30 sec • 5 pts

A cookie can not be used to control a users session/state

False. Cookies are often used for tracking sessions

True, only supercookies have this feature

3.

MULTIPLE CHOICE QUESTION

30 sec • 5 pts

What is IDOR?

Insecure Door or Room

Invalid Data or Reference

Insecure Direct Object Reference

4.

MULTIPLE CHOICE QUESTION

30 sec • 5 pts

What is SQL injection?

It is used to spoof or inject false headers in a HTTP request

It is used in Buffer Overflow attacks to overwrite memory

It is used to inject malicious code to a database server, through a query

5.

MULTIPLE CHOICE QUESTION

30 sec • 5 pts

What is the best practice in defending against SQL injection?

Blocking specific ports that SQL injections are usually attacked via

Programmers will not make web applications that allow user input

Sanitizing users input in a web application

6.

MULTIPLE CHOICE QUESTION

30 sec • 5 pts

Netsparker and Burp Suite Professional are examples of:

Web-focused vulnerability detection tools

VPNs

Web application firewalls

Antimalware

7.

MULTIPLE CHOICE QUESTION

30 sec • 5 pts

Which of the following is not an example of an XSS attack?

Stored XSS

DOM-based XSS

Reflected XSS

DNS XSS

Create a free account and access millions of resources

Create resources
Host any resource
Get auto-graded reports
or continue with
Microsoft
Apple
Others
By signing up, you agree to our Terms of Service & Privacy Policy
Already have an account?

Discover more resources for Instructional Technology