Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Web Security Quiz

Total questions: 50

Worksheet time: 38mins

Name
Class
Date
1.

Which of the following is a principle related to browser security?

a)

Browser Security Principles

b)

Data Mining Techniques

c)

Network Routing Protocols

d)

Cloud Storage Solutions

2.

A company wants to secure its application using both client-side and server-side security. What is a strategic reason for this approach?

a)

To provide layered protection against different types of attacks

b)

To reduce the number of users

c)

To increase the size of the database

d)

To improve color accuracy in images

3.

Which of the following best describes the primary function of a web browser?

a)

It is a tool for creating web applications.

b)

It is the gateway between users and the web applications they access.

c)

It is used to design websites.

d)

It is a type of operating system.

4.

Why is the scenario "http://www.example.com/home → https://www.example.com/home" blocked?

a)

Different domain

b)

Different protocol

c)

Different port

d)

Same protocol, domain, and port

5.

A request from https://www.example.com:443/home to https://www.example.com:8080/home is blocked. What is the reason for this?

a)

Different protocol

b)

Different domain

c)

Different port

d)

Same protocol, domain, and port

6.

What are the two main components that web applications work with?

a)

Database and network

b)

Client-side and server-side

c)

Front-end and back-end only

d)

User interface and operating system

7.

On which side do logic, data, and processing of a web application typically occur?

a)

Client-side

b)

User interface

c)

Server-side

d)

Browser cache

8.

A user is interacting with a web application through their browser. Which component are they using?

a)

Server-side

b)

Database

c)

Client-side

d)

Network layer

9.

A potential benefit of moving some processing from the server to the client in a web application is:

a)

Increased server load

b)

Reduced server load and faster user interactions

c)

Slower user experience

d)

More complex server logic

10.

Where do client-side frameworks run?

a)

On the user's browser

b)

On the web server

c)

On the database server

d)

On the network switch

11.

Why do developers use client-side frameworks instead of writing everything from scratch?

a)

They use pre-made "building blocks" called frameworks

b)

They want to avoid using any code libraries

c)

They prefer to write all code manually for better security

d)

They need to reduce the number of users on the website

12.

Which frameworks are used to handle complex pages without refreshing the website?

a)

SPA frameworks (React, Angular, Vue)

b)

CSS frameworks (Bootstrap, Bulma)

c)

Database frameworks (MongoDB, MySQL)

d)

Web server frameworks (Express, Flask)

13.

A security analyst finds that a web application is leaking its software version in the response headers. What is the most appropriate mitigation step?

a)

Update or mask the HTTP headers to hide software/version info

b)

Increase the server's bandwidth

c)

Change the website's color scheme

d)

Add more user accounts

14.

Which of the following best describes a Stored XSS attack?

a)

Malicious script is stored in the database and runs whenever a user loads the page.

b)

Script is immediately reflected back from the server.

c)

Script executes entirely in the browser by manipulating the DOM.

d)

Malicious script is sent via email to users.

15.

Which type of XSS attack involves the script being immediately reflected back from the server, such as through a URL or form?

a)

Reflected XSS

b)

Stored XSS

c)

DOM-based XSS

d)

Persistent XSS

16.

What is a possible impact of an XSS attack?

a)

Stealing sensitive data like session cookies or login tokens

b)

Encrypting files for ransom

c)

Deleting files from the server

d)

Slowing down the website

17.

Which of the following best describes how an attacker exploits Stored XSS?

a)

By uploading malicious code into a website’s input field.

b)

By sending phishing emails to users.

c)

By brute-forcing user passwords.

d)

By exploiting server misconfigurations.

18.

The most likely consequence of a website allowing users to post comments without sanitizing input is:

a)

The script will run for every user who views the comment, potentially stealing data or hijacking accounts.

b)

The website will crash immediately.

c)

Only the attacker will see the script execute.

d)

The comment will be automatically deleted.

19.

Which part of a web page does DOM-based XSS exploit?

a)

Document Object Model (DOM)

b)

Cascading Style Sheets (CSS)

c)

Server-side scripts

d)

Database queries

20.

Why is DOM-based XSS harder to detect than other types of XSS?

a)

Because static analysis tools and traditional scanners often look for server-side issues.

b)

Because it always requires user authentication.

c)

Because it only affects outdated browsers.

d)

Because it is always stored in the database.

21.

Suppose a security analyst is using a traditional scanner to detect XSS vulnerabilities. Why might they miss a DOM-based XSS vulnerability?

a)

Because traditional scanners often focus on server-side issues, not client-side vulnerabilities.

b)

Because DOM-based XSS only affects the server.

c)

Because DOM-based XSS is always visible in the source code.

d)

Because traditional scanners are designed for network attacks.

22.

Which of the following best describes a "source" in the context of Reflected XSS?

a)

A DOM object that can store or receive user input, such as window.location.search or window.location.hash.

b)

A DOM API that executes or renders input, such as document.write() or eval().

c)

A server-side script that processes user data.

d)

A database that stores user credentials.

23.

What happens if a web page uses user input from the URL without sanitization in Reflected XSS?

a)

An attacker can inject malicious scripts.

b)

The server will block the request.

c)

The browser will automatically sanitize the input.

d)

The input will be ignored.

24.

What is the main feature that distinguishes Mutation-Based XSS (mXSS) from traditional XSS attacks?

a)

It exploits how browsers process and mutate HTML and DOM elements after the page has loaded.

b)

It only affects outdated browsers.

c)

It relies on user input validation.

d)

It is always detected by antivirus software.

25.

Why is Mutation-Based XSS considered very hard to detect and mitigate?

a)

Because it exploits browser-specific DOM behavior and parsing quirks.

b)

Because it only affects old browsers.

c)

Because it is always visible in the page source.

d)

Because it requires no user interaction.

26.

What is a key reason why mXSS is more challenging to mitigate than traditional XSS?

a)

It is very hard to detect and mitigate compared to traditional XSS.

b)

It only affects static websites.

c)

It does not use JavaScript.

d)

It is always blocked by firewalls.

27.

What is the main role of browser mutation in Mutation-Based XSS attacks?

a)

It encrypts the payload before sending it to the server.

b)

It parses and optimizes the DOM, potentially altering tags, attributes, or quote structures.

c)

It blocks all unsafe scripts from executing in the browser.

d)

It compresses the payload to reduce network traffic.

28.

What is a common method to prevent XSS attacks in web applications?

a)

Input validation and output encoding.

b)

Using only HTTPS connections.

c)

Regularly updating the server software.

d)

Limiting user access to the database.

29.

Which of the following is a characteristic of DOM-based XSS?

a)

It can only be executed on mobile devices.

b)

It is always stored in the database.

c)

It requires server-side processing to be effective.

d)

It manipulates the DOM to execute scripts.

30.

What is the primary goal of a Cross-Site Scripting (XSS) attack?

a)

To redirect users to a different website.

b)

To steal user passwords directly from the database.

c)

To overload the server with requests.

d)

To execute malicious scripts in the context of a user's session.

31.

What is the primary purpose of using HTTPS in web applications?

a)

To increase the number of users

b)

To encrypt data transmitted between the client and server

c)

To enhance the visual design of the website

d)

To improve loading speed

32.

Which of the following is a common vulnerability in web applications that allows attackers to inject malicious scripts?

a)

Cross-Site Scripting (XSS)

b)

Man-in-the-Middle (MitM)

c)

SQL Injection

d)

Denial of Service (DoS)

33.

What is a common technique used to prevent Cross-Site Request Forgery (CSRF) attacks?

a)

Using CAPTCHA on forms

b)

Encrypting data in transit

c)

Implementing anti-CSRF tokens

d)

Validating user input

34.

What is a common consequence of failing to implement Content Security Policy (CSP) in a web application?

a)

Improved user experience.

b)

Reduced server costs.

c)

Increased loading times for the website.

d)

Higher risk of XSS attacks.

35.

Which of the following is a method to detect XSS vulnerabilities during the development phase?

a)

Implementing user authentication.

b)

Code reviews and static analysis tools.

c)

Using a content delivery network (CDN).

d)

Increasing server capacity.

36.

What is the role of the Same-Origin Policy in web security?

a)

It enhances the performance of web applications.

b)

It is used to encrypt data in transit.

c)

It allows all origins to access each other's resources freely.

d)

It restricts how documents or scripts loaded from one origin can interact with resources from another origin.

37.

What is the main advantage of using a Content Security Policy (CSP) in web applications?

a)

To increase the number of visitors

b)

To enhance server performance

c)

To prevent unauthorized script execution

d)

To improve website aesthetics

38.

Which of the following is a common technique to mitigate SQL injection attacks?

a)

Allowing all user inputs

b)

Using prepared statements and parameterized queries

c)

Disabling database access

d)

Using only GET requests

39.

What is the purpose of using input sanitization in web applications?

a)

To ensure data is stored in the database

b)

To prevent malicious data from being processed

c)

To improve the speed of data retrieval

d)

To enhance user interface design

40.

What is the primary function of a web application firewall (WAF)?

a)

To filter and monitor HTTP traffic to and from a web application

b)

To monitor network traffic

c)

To store user data securely

d)

To enhance the visual design of web pages

41.

Which of the following is a common method for securing APIs in web applications?

a)

Using API keys and tokens

b)

Allowing unrestricted access to all users

c)

Storing all data in plain text

d)

Using only GET requests

42.

What is the main purpose of using HTTPS instead of HTTP?

a)

To improve website aesthetics

b)

To encrypt data exchanged between the client and server

c)

To increase the loading speed of the website

d)

To allow more users to access the site simultaneously

43.

What is a common way to mitigate SQL Injection attacks in web applications?

a)

Using prepared statements and parameterized queries.

b)

Implementing CAPTCHA on forms.

c)

Increasing server bandwidth.

d)

Regularly changing the website's theme.

44.

What is the main advantage of using Content Security Policy (CSP) in web applications?

a)

To prevent unauthorized script execution.

b)

To improve website loading speed.

c)

To allow cross-origin resource sharing.

d)

To enhance the visual design of web pages.

45.

Which of the following is a common indicator of a potential Cross-Site Scripting (XSS) vulnerability?

a)

High server response time.

b)

Low website traffic.

c)

Presence of user-generated content without sanitization.

d)

Frequent database errors.

46.

What is a common vulnerability associated with improperly configured web applications?

a)

SQL Injection

b)

Data Encryption

c)

Session Management

d)

Network Latency

47.

Which of the following is a method to enhance security in web applications?

a)

Implementing Content Security Policy (CSP)

b)

Using only HTTP connections

c)

Disabling user authentication

d)

Allowing all cross-origin requests

48.

What is the primary function of a Web Application Firewall (WAF)?

a)

To manage database queries

b)

To improve website loading speed

c)

To filter and monitor HTTP traffic to and from a web application

d)

To store user data securely

49.

What is a common technique to secure user input in web applications?

a)

Input validation

b)

Allowing all input types

c)

Disabling JavaScript

d)

Using plain text storage

50.

Which of the following is a best practice for managing user sessions in web applications?

a)

Sharing session IDs via URL

b)

Using secure, HttpOnly cookies

c)

Storing session data in local storage

d)

Keeping sessions active indefinitely