WorksheetsWeb Security Quiz
Total questions: 50
Worksheet time: 38mins
Which of the following is a principle related to browser security?
Browser Security Principles
Data Mining Techniques
Network Routing Protocols
Cloud Storage Solutions
A company wants to secure its application using both client-side and server-side security. What is a strategic reason for this approach?
To provide layered protection against different types of attacks
To reduce the number of users
To increase the size of the database
To improve color accuracy in images
Which of the following best describes the primary function of a web browser?
It is a tool for creating web applications.
It is the gateway between users and the web applications they access.
It is used to design websites.
It is a type of operating system.
Why is the scenario "http://www.example.com/home → https://www.example.com/home" blocked?
Different domain
Different protocol
Different port
Same protocol, domain, and port
A request from https://www.example.com:443/home to https://www.example.com:8080/home is blocked. What is the reason for this?
Different protocol
Different domain
Different port
Same protocol, domain, and port
What are the two main components that web applications work with?
Database and network
Client-side and server-side
Front-end and back-end only
User interface and operating system
On which side do logic, data, and processing of a web application typically occur?
Client-side
User interface
Server-side
Browser cache
A user is interacting with a web application through their browser. Which component are they using?
Server-side
Database
Client-side
Network layer
A potential benefit of moving some processing from the server to the client in a web application is:
Increased server load
Reduced server load and faster user interactions
Slower user experience
More complex server logic
Where do client-side frameworks run?
On the user's browser
On the web server
On the database server
On the network switch
Why do developers use client-side frameworks instead of writing everything from scratch?
They use pre-made "building blocks" called frameworks
They want to avoid using any code libraries
They prefer to write all code manually for better security
They need to reduce the number of users on the website
Which frameworks are used to handle complex pages without refreshing the website?
SPA frameworks (React, Angular, Vue)
CSS frameworks (Bootstrap, Bulma)
Database frameworks (MongoDB, MySQL)
Web server frameworks (Express, Flask)
A security analyst finds that a web application is leaking its software version in the response headers. What is the most appropriate mitigation step?
Update or mask the HTTP headers to hide software/version info
Increase the server's bandwidth
Change the website's color scheme
Add more user accounts
Which of the following best describes a Stored XSS attack?
Malicious script is stored in the database and runs whenever a user loads the page.
Script is immediately reflected back from the server.
Script executes entirely in the browser by manipulating the DOM.
Malicious script is sent via email to users.
Which type of XSS attack involves the script being immediately reflected back from the server, such as through a URL or form?
Reflected XSS
Stored XSS
DOM-based XSS
Persistent XSS
What is a possible impact of an XSS attack?
Stealing sensitive data like session cookies or login tokens
Encrypting files for ransom
Deleting files from the server
Slowing down the website
Which of the following best describes how an attacker exploits Stored XSS?
By uploading malicious code into a website’s input field.
By sending phishing emails to users.
By brute-forcing user passwords.
By exploiting server misconfigurations.
The most likely consequence of a website allowing users to post comments without sanitizing input is:
The script will run for every user who views the comment, potentially stealing data or hijacking accounts.
The website will crash immediately.
Only the attacker will see the script execute.
The comment will be automatically deleted.
Which part of a web page does DOM-based XSS exploit?
Document Object Model (DOM)
Cascading Style Sheets (CSS)
Server-side scripts
Database queries
Why is DOM-based XSS harder to detect than other types of XSS?
Because static analysis tools and traditional scanners often look for server-side issues.
Because it always requires user authentication.
Because it only affects outdated browsers.
Because it is always stored in the database.
Suppose a security analyst is using a traditional scanner to detect XSS vulnerabilities. Why might they miss a DOM-based XSS vulnerability?
Because traditional scanners often focus on server-side issues, not client-side vulnerabilities.
Because DOM-based XSS only affects the server.
Because DOM-based XSS is always visible in the source code.
Because traditional scanners are designed for network attacks.
Which of the following best describes a "source" in the context of Reflected XSS?
A DOM object that can store or receive user input, such as window.location.search or window.location.hash.
A DOM API that executes or renders input, such as document.write() or eval().
A server-side script that processes user data.
A database that stores user credentials.
What happens if a web page uses user input from the URL without sanitization in Reflected XSS?
An attacker can inject malicious scripts.
The server will block the request.
The browser will automatically sanitize the input.
The input will be ignored.
What is the main feature that distinguishes Mutation-Based XSS (mXSS) from traditional XSS attacks?
It exploits how browsers process and mutate HTML and DOM elements after the page has loaded.
It only affects outdated browsers.
It relies on user input validation.
It is always detected by antivirus software.
Why is Mutation-Based XSS considered very hard to detect and mitigate?
Because it exploits browser-specific DOM behavior and parsing quirks.
Because it only affects old browsers.
Because it is always visible in the page source.
Because it requires no user interaction.
What is a key reason why mXSS is more challenging to mitigate than traditional XSS?
It is very hard to detect and mitigate compared to traditional XSS.
It only affects static websites.
It does not use JavaScript.
It is always blocked by firewalls.
What is the main role of browser mutation in Mutation-Based XSS attacks?
It encrypts the payload before sending it to the server.
It parses and optimizes the DOM, potentially altering tags, attributes, or quote structures.
It blocks all unsafe scripts from executing in the browser.
It compresses the payload to reduce network traffic.
What is a common method to prevent XSS attacks in web applications?
Input validation and output encoding.
Using only HTTPS connections.
Regularly updating the server software.
Limiting user access to the database.
Which of the following is a characteristic of DOM-based XSS?
It can only be executed on mobile devices.
It is always stored in the database.
It requires server-side processing to be effective.
It manipulates the DOM to execute scripts.
What is the primary goal of a Cross-Site Scripting (XSS) attack?
To redirect users to a different website.
To steal user passwords directly from the database.
To overload the server with requests.
To execute malicious scripts in the context of a user's session.
What is the primary purpose of using HTTPS in web applications?
To increase the number of users
To encrypt data transmitted between the client and server
To enhance the visual design of the website
To improve loading speed
Which of the following is a common vulnerability in web applications that allows attackers to inject malicious scripts?
Cross-Site Scripting (XSS)
Man-in-the-Middle (MitM)
SQL Injection
Denial of Service (DoS)
What is a common technique used to prevent Cross-Site Request Forgery (CSRF) attacks?
Using CAPTCHA on forms
Encrypting data in transit
Implementing anti-CSRF tokens
Validating user input
What is a common consequence of failing to implement Content Security Policy (CSP) in a web application?
Improved user experience.
Reduced server costs.
Increased loading times for the website.
Higher risk of XSS attacks.
Which of the following is a method to detect XSS vulnerabilities during the development phase?
Implementing user authentication.
Code reviews and static analysis tools.
Using a content delivery network (CDN).
Increasing server capacity.
What is the role of the Same-Origin Policy in web security?
It enhances the performance of web applications.
It is used to encrypt data in transit.
It allows all origins to access each other's resources freely.
It restricts how documents or scripts loaded from one origin can interact with resources from another origin.
What is the main advantage of using a Content Security Policy (CSP) in web applications?
To increase the number of visitors
To enhance server performance
To prevent unauthorized script execution
To improve website aesthetics
Which of the following is a common technique to mitigate SQL injection attacks?
Allowing all user inputs
Using prepared statements and parameterized queries
Disabling database access
Using only GET requests
What is the purpose of using input sanitization in web applications?
To ensure data is stored in the database
To prevent malicious data from being processed
To improve the speed of data retrieval
To enhance user interface design
What is the primary function of a web application firewall (WAF)?
To filter and monitor HTTP traffic to and from a web application
To monitor network traffic
To store user data securely
To enhance the visual design of web pages
Which of the following is a common method for securing APIs in web applications?
Using API keys and tokens
Allowing unrestricted access to all users
Storing all data in plain text
Using only GET requests
What is the main purpose of using HTTPS instead of HTTP?
To improve website aesthetics
To encrypt data exchanged between the client and server
To increase the loading speed of the website
To allow more users to access the site simultaneously
What is a common way to mitigate SQL Injection attacks in web applications?
Using prepared statements and parameterized queries.
Implementing CAPTCHA on forms.
Increasing server bandwidth.
Regularly changing the website's theme.
What is the main advantage of using Content Security Policy (CSP) in web applications?
To prevent unauthorized script execution.
To improve website loading speed.
To allow cross-origin resource sharing.
To enhance the visual design of web pages.
Which of the following is a common indicator of a potential Cross-Site Scripting (XSS) vulnerability?
High server response time.
Low website traffic.
Presence of user-generated content without sanitization.
Frequent database errors.
What is a common vulnerability associated with improperly configured web applications?
SQL Injection
Data Encryption
Session Management
Network Latency
Which of the following is a method to enhance security in web applications?
Implementing Content Security Policy (CSP)
Using only HTTP connections
Disabling user authentication
Allowing all cross-origin requests
What is the primary function of a Web Application Firewall (WAF)?
To manage database queries
To improve website loading speed
To filter and monitor HTTP traffic to and from a web application
To store user data securely
What is a common technique to secure user input in web applications?
Input validation
Allowing all input types
Disabling JavaScript
Using plain text storage
Which of the following is a best practice for managing user sessions in web applications?
Sharing session IDs via URL
Using secure, HttpOnly cookies
Storing session data in local storage
Keeping sessions active indefinitely
