web Security

web Security

University

8 Qs

quiz-placeholder

Similar activities

Data Science Quiz

Data Science Quiz

University

11 Qs

Taller SO C2 - Usuarios y SSH

Taller SO C2 - Usuarios y SSH

University

10 Qs

CN3303 - Lecture 9: Cloud Security threats

CN3303 - Lecture 9: Cloud Security threats

University

10 Qs

CM QUIZ

CM QUIZ

University

11 Qs

แบบทบทวน RMS

แบบทบทวน RMS

University

12 Qs

UTS SI. Kemanan Sistem Informasi

UTS SI. Kemanan Sistem Informasi

University

10 Qs

Quiz Pem Mobile

Quiz Pem Mobile

University

10 Qs

Cybersecurity

Cybersecurity

University

12 Qs

web Security

web Security

Assessment

Quiz

Computers

University

Practice Problem

Medium

Created by

Sahra Abukar

Used 4+ times

FREE Resource

AI

Enhance your content in a minute

Add similar questions
Adjust reading levels
Convert to real-world scenario
Translate activity
More...

8 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

20 sec • 1 pt

Which OWASP resource is crucial for developers to understand and mitigate web security risks?

OWASP Secure Coding Guidelines

OWASP Top 10

OWASP ZAP

OWASP Defenders

2.

MULTIPLE CHOICE QUESTION

20 sec • 1 pt

What vulnerability involves unsanitized user input executing unintended commands?

XSS (Cross-Site Scripting)

CSRF (Cross-Site Request Forgery)

SQL Injection

SSRF (Server-Side Request Forgery)

3.

MULTIPLE CHOICE QUESTION

20 sec • 1 pt

Which OWASP Top10 involves allowing users to access restricted resources or functionalities outside their assigned role​

A01:2021– Broken Access Control

A04:2021–Insecure Design

A06:2021–Vulnerable and Outdated Components

A07:2021–Identification and Authentication Failures

4.

MULTIPLE CHOICE QUESTION

20 sec • 1 pt

Which OWASP Top 10 category does 'using components with known vulnerabilities' fall under?

A05:2021–Security Misconfiguration

A08:2021–Software and Data Integrity Failures

A10:2021–Log4j

A06:2021–Vulnerable and Outdated Components

5.

MULTIPLE CHOICE QUESTION

20 sec • 1 pt

What is a primary defense against 'Injection' flaws according to OWASP?

Client-side validation

Strong encryption

Input validation

Frequent password changes

6.

MULTIPLE CHOICE QUESTION

20 sec • 1 pt

Which one of the following is NOT a prevention method for OWASP top 10 'Identification and Authentication Failures'

Implementing multi-authentication​

Using default usernames and passwords

Aligning password policies with the latest NIST standards

report failed login attempts and notify administrators of possible attacks.

7.

MULTIPLE CHOICE QUESTION

20 sec • 1 pt

For 'Identification and Authentication Failures' which standard does OWASP recommend aligning password policies with?

IEEE 802.11

ISO/IEC 27001

NIST

OWASP itself

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?

Discover more resources for Computers