Font size
WorksheetsHacker-Powered Security Report 2024-25
Total questions: 10
Worksheet time: 7mins
According to 8th edition of Hacker-Powered Security Report 2024-25, what is the top vulnerability reported to a bug bounty program?
Misconfiguration
Cross-site scripting (XSS)
Sensitive information disclosure
Business logic errors
True or False: According to 8th edition of Hacker-Powered Security Report 2024-25, HackerOne has seen a 67% increase in pentesting over the past year.
True
False
According to 8th edition of Hacker-Powered Security Report 2024-25, what is the average number of researchers on a high-impact program?
34
9
56
171
According to Jasmin Landry, Security Researcher and HackerOne Pentester, cited in 8th edition of Hacker-Powered Security Report 2024-25, what is a significant risk posed by AI?
Training-data leaks
Unauthorized AI usage within organizations
The hacking of AI models by external parties
AI introducing more vulnerabilities
What are some recommendations for running a top-tier security program found in the 8th edition of Hacker-Powered Security Report 2024-25?
Offer constructive feedback on reports.
Offer the highest bounties possible.
Clearly communicate expected response times.
Respond to researchers with respect and professionalism.
True or False: The concept of return on mitigation (ROM) was recently introduced by HackerOne.
True
False
What are the three key traits of high-impact bug bounty programs according to the 8th edition of Hacker-Powered Security Report 2024-25?
Higher bounties
Smaller, focused communities
Stricter acceptance criteria for researchers
Broader testing scope
What are some recommendations for securing a budget for proactive security measures, according to the 8th edition of Hacker-Powered Security Report 2024-25?
Focus on showcasing cost savings
Make a strong business case
Identify the critical systems in scope for the program
Prepare for unexpected high-severity vulnerabilities
Match the industry with its featured vulnerability as highlighted in the 8th edition of Hacker-Powered Security Report 2024-25:
Financial Services
Insecure direct object reference (IDOR)
Government
Cross-site scripting (XSS)
Telecoms
Improper Authentication
Retail and E-Commerce
Information Disclosure
Crypto and Blockchain
Business Logic Errors
According to the 8th edition of Hacker-Powered Security Report 2024-25, how much of an organization's budget will be spent on the top 10 common vulnerabilities?
54%
63%
72%
81%
