
Web Application Security Quiz
Quiz
•
Computers
•
University
•
Practice Problem
•
Hard
Keitumetse Taumoloko
Used 1+ times
FREE Resource
Enhance your content in a minute
15 questions
Show all answers
1.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
What is the main difference between content spoofing and reflected XSS?
Content spoofing is a subset of XSS, while reflected XSS involves submitting malicious javascript code in HTTP requests
Content spoofing uses advanced javascript frameworks, while reflected XSS considers the types of input in HTTP requests
Content spoofing involves running attack-driven code in the client browser, while reflected XSS hides legitimate page content with absolutely positioned elements
Content spoofing allows users to change a portion of the URL to modify content directly, while reflected XSS involves tampering with HTTP requests
2.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
What is the first line of defense for every web application against XSS?
Html validation and sanitisation
Secure JSON patterns
Contextual output encoding
Input validation
3.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which technique converts data to a form that is display-only and prevents the execution of javascript or rendering of HTML tags?
Html validation and sanitisation
Input validation
Secure JSON patterns
Contextual output encoding
4.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
When should you use HTML validation and sanitisation?
When you want to allow all HTML without any restrictions
When you want users to submit any HTML to your website
When you want to allow only a limited subset of HTML and remove dangerous attributes
When you want to eliminate all HTML from user submissions
5.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
What is the purpose of using secure JSON patterns in web applications?
To deliver an HTML file without data and then populate it with JSON
To populate HTML files with untrusted data directly
To increase the attack surface by allowing untrusted data in JSON
To prevent XSS attacks by parsing JSON data using the eval function
6.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which context requires different encoding methods depending on where untrusted data is inserted into the webpage?
Javascript block content
Javascript attribute context
Attribute context
HTML context
7.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
What is the recommended approach to parse JSON data in modern applications?
Use JSON.parse to avoid untrusted data in JSON
Use the eval function to prevent untrusted data from coming through
Use HTML sanitisation to parse JSON data
Use unpopulated HTML files for JSON data
Access all questions and much more by creating a free account
Create resources
Host any resource
Get auto-graded reports

Continue with Google

Continue with Email

Continue with Classlink

Continue with Clever
or continue with

Microsoft
%20(1).png)
Apple
Others
Already have an account?
Similar Resources on Wayground
10 questions
Server Administration- Quiz 1
Quiz
•
12th Grade - University
19 questions
Informatika Kelas 5 Bab 2
Quiz
•
5th Grade - University
14 questions
Semi-Long Quiz#1 - SAM, NW3A-3E
Quiz
•
University
12 questions
CIS1103 Week 9_10 CLO3 Part 1
Quiz
•
University
20 questions
NACOS Kahoot Session II
Quiz
•
University
20 questions
COA_QUIZ_UNIT I
Quiz
•
University
12 questions
PSSI Chp 1 dan 2
Quiz
•
University
12 questions
ASAS SAINS KOMPUTER : TINGKATAN 3
Quiz
•
4th Grade - University
Popular Resources on Wayground
15 questions
Fractions on a Number Line
Quiz
•
3rd Grade
20 questions
Equivalent Fractions
Quiz
•
3rd Grade
25 questions
Multiplication Facts
Quiz
•
5th Grade
22 questions
fractions
Quiz
•
3rd Grade
20 questions
Main Idea and Details
Quiz
•
5th Grade
20 questions
Context Clues
Quiz
•
6th Grade
15 questions
Equivalent Fractions
Quiz
•
4th Grade
20 questions
Figurative Language Review
Quiz
•
6th Grade
