Lecture 14: Cross Site Scripting attacks

Lecture 14: Cross Site Scripting attacks

8 Qs

quiz-placeholder

Similar activities

Computer Lab Rules & Behaviors

Computer Lab Rules & Behaviors

6th - 8th Grade

10 Qs

IPO QUIZ Class 3

IPO QUIZ Class 3

3rd Grade

12 Qs

Staff CPD Internet Safety and AI Quizizz

Staff CPD Internet Safety and AI Quizizz

10th Grade

10 Qs

Software-Chapter 6

Software-Chapter 6

7th - 10th Grade

10 Qs

ASK

ASK

3rd Grade

11 Qs

online sharing

online sharing

Professional Development

10 Qs

EMPOWERMENT TECHNOLOGIES – QUIZ 7 [New]

EMPOWERMENT TECHNOLOGIES – QUIZ 7 [New]

11th Grade

10 Qs

Network Protocols AS DigiTech

Network Protocols AS DigiTech

2nd Grade

10 Qs

Lecture 14: Cross Site Scripting attacks

Lecture 14: Cross Site Scripting attacks

Assessment

Quiz

Computers

Practice Problem

Hard

Created by

Alejandro Gomez

Used 3+ times

FREE Resource

AI

Enhance your content in a minute

Add similar questions
Adjust reading levels
Convert to real-world scenario
Translate activity
More...

8 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

Is web browsing stateful or stateless?

Stateful

Stateless

Both

All answers are valid

2.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

What's the main purpose of a cookie?

To sniff user traffic in order to authenticate the user on a website

To verify the version of the browser the user is using to access a website

To enable web servers to store stateful information on the user's device or to track the user's browsing activity

All answers are correct

3.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

Which header can we use to ensure a cookie can only be accessed using HTTP or HTTPs but not using javascript?

Secure cookie

HttpOnly cookie

Persistent cookie

Third party cookie

4.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

Which are the three main types of XSS attacks?

reflected, redirected, persistent

reflected, csrf , persistent

injected, persistent and reflected

persistent, reflected and DOM based

5.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

How can XSS attacks be prevented?

Blocking the execution of local website javascript content

Filtering input on arrival and encoding output

Using appropriate response headers and Content Security Policies

All answers are correct.

6.

MULTIPLE CHOICE QUESTION

45 sec • 1 pt

What kind of attack did Samy Kamkar triggered in myspace?

Reflected XSS

SQLi

Stored XSS

CSRF

7.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

What is the different between stateful and stateless apps?

Stateless apps require to store the users session on the server, while stateful apps don't require it

Stateful apps require to store the users session on the server, while stateless apps don't require it

Stateful apps uses signed JWT tokens that are stored on the client side, while stateless apps use cookies

Stateless apps uses signed JWT tokens that are stored on the client side, while stateful apps use cookies

8.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

How can CSRF attacks be prevented?

Using a referer header

Using a CSRF token

Using a javascript signed cookie

All of the answers are correct