Happy hour Week 30

Happy hour Week 30

KG

10 Qs

quiz-placeholder

Similar activities

15NovTeamMeeting

15NovTeamMeeting

Professional Development

10 Qs

Reta numérica

Reta numérica

Professional Development

12 Qs

HTML Day 1

HTML Day 1

Professional Development

11 Qs

Software Development

Software Development

Professional Development

9 Qs

HTML Basics

HTML Basics

Professional Development

15 Qs

TECHNICIAN L2 - ENGINE

TECHNICIAN L2 - ENGINE

Professional Development

12 Qs

Tribe Night

Tribe Night

Professional Development

11 Qs

GFG Quiz

GFG Quiz

11th Grade - Professional Development

10 Qs

Happy hour Week 30

Happy hour Week 30

Assessment

Quiz

Professional Development

KG

Medium

Created by

Checkmarx Rocha

Used 2+ times

FREE Resource

10 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is needed to succeed in a Prototype Pollution attack?

only to "override" a __proto__ property or method

only need to call on a gadget

only to pollute a property or method and have a gadget to call it

only HTML injection allows Prototype pollution

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of the following payloads allows to check for HTML Injection?

<script>alert()</script>

<b>test</b>

<img src="something" onerror="do()">

' AND 1=1'

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Does STRUTS prevent CSRF?

YES

NO

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Why are 3rd party libs excluded from CxSAST analysis ?

Those are scanned by Composition Analysis

Those are manually analysed by AppSec Research

Those are not excluded

KICS scans those

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is KICS?

keeping infrastructure as code scanner

keeping intelligent code secure

keeping infrastructure as code safe

keeping infrastructure as code secure

6.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is parameter tampering?

a program inadvertently exposes sensitive information provided without proper encryption or protection.

an attacker alters input parameters to bypass controls or gain unauthorized access to a system or application.

an exception raised during an operation is not properly handled, causing the program to terminate abruptly with an error message.

an application fails to properly handle and restrict XML input containing external entities, potentially leading to information disclosure.

7.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is Prompt Engineering?

the physical construction or design of engineering prompts for user mechanical devices.

the process of designing instructions given during a CICD pipeline to achieve quality standards.

is the overall impression and satisfaction a person gains from interacting with a product, service, or system, encompassing aspects like usability, accessibility, and emotional response.

the process of designing and optimizing prompts for natural language processing models to enhance their performance and generate more accurate responses.

Create a free account and access millions of resources

Create resources
Host any resource
Get auto-graded reports
or continue with
Microsoft
Apple
Others
By signing up, you agree to our Terms of Service & Privacy Policy
Already have an account?