Search Header Logo

Security Engineer Intern

Authored by Rizwaan Bashir

Information Technology (IT)

University

Used 1+ times

Security Engineer Intern
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

28 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

10 sec • 1 pt

What does setting `SameSite=Strict` on cookies help prevent?

XSS
CSRF
Clickjacking
CORS issues

2.

MULTIPLE CHOICE QUESTION

10 sec • 1 pt

Which header protects against Clickjacking attacks?

Content-Type
X-Content-Type-Options
X-Frame-Options
Cache-Control

3.

MULTIPLE CHOICE QUESTION

10 sec • 1 pt

In a broken access control test, what’s the best way to discover IDOR?

XSS injection
Changing URL parameters
Clearing cookies
Changing HTTP method

4.

MULTIPLE CHOICE QUESTION

10 sec • 1 pt

In OAuth, what is the purpose of the `state` parameter?

Session tracking
Scope restriction
CSRF protection
Token refresh

5.

MULTIPLE CHOICE QUESTION

10 sec • 1 pt

You bypass a login by modifying a JWT’s algorithm to `none`. What’s this flaw?

Key reuse
Signature validation bypass
Replay attack
Session fixation

6.

MULTIPLE CHOICE QUESTION

10 sec • 1 pt

What does SSRF in a cloud app often lead to?

XSS
IAM access
File upload
Shellshock

7.

MULTIPLE CHOICE QUESTION

10 sec • 1 pt

Which AWS service metadata IP is often targeted by SSRF?

127.0.0.1
0.0.0.0
169.254.169.254
192.168.1.1

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?