
Security Engineer Intern
Authored by Rizwaan Bashir
Information Technology (IT)
University
Used 1+ times

AI Actions
Add similar questions
Adjust reading levels
Convert to real-world scenario
Translate activity
More...
Content View
Student View
28 questions
Show all answers
1.
MULTIPLE CHOICE QUESTION
10 sec • 1 pt
What does setting `SameSite=Strict` on cookies help prevent?
XSS
CSRF
Clickjacking
CORS issues
2.
MULTIPLE CHOICE QUESTION
10 sec • 1 pt
Which header protects against Clickjacking attacks?
Content-Type
X-Content-Type-Options
X-Frame-Options
Cache-Control
3.
MULTIPLE CHOICE QUESTION
10 sec • 1 pt
In a broken access control test, what’s the best way to discover IDOR?
XSS injection
Changing URL parameters
Clearing cookies
Changing HTTP method
4.
MULTIPLE CHOICE QUESTION
10 sec • 1 pt
In OAuth, what is the purpose of the `state` parameter?
Session tracking
Scope restriction
CSRF protection
Token refresh
5.
MULTIPLE CHOICE QUESTION
10 sec • 1 pt
You bypass a login by modifying a JWT’s algorithm to `none`. What’s this flaw?
Key reuse
Signature validation bypass
Replay attack
Session fixation
6.
MULTIPLE CHOICE QUESTION
10 sec • 1 pt
What does SSRF in a cloud app often lead to?
XSS
IAM access
File upload
Shellshock
7.
MULTIPLE CHOICE QUESTION
10 sec • 1 pt
Which AWS service metadata IP is often targeted by SSRF?
127.0.0.1
0.0.0.0
169.254.169.254
192.168.1.1
Access all questions and much more by creating a free account
Create resources
Host any resource
Get auto-graded reports

Continue with Google

Continue with Email

Continue with Classlink

Continue with Clever
or continue with

Microsoft
%20(1).png)
Apple
Others
Already have an account?