NEW
Font size
S
M
L
XL
Worksheets02 OWASP URGENT
Total questions: 30
Worksheet time: 15mins
Name
Class
Date
1.
What does OWASP stand for?
a)
Open Web Application Security Project
b)
Online Web Access Safety Plan
c)
Open Web App Software Policy
d)
Operational Web App System
2.
What is the purpose of OWASP?
a)
Create antivirus tools
b)
Improve software security
c)
Manage firewalls
d)
Audit network hardware
3.
What is the OWASP Top 10?
a)
A ranking of web security risks
b)
A list of programming languages
c)
A set of design templates
d)
A database of malware
4.
How often is the OWASP Top 10 updated?
a)
Every 2 years
b)
Every 3–4 years
c)
Every 10 years
d)
Monthly
5.
What type of organization is OWASP?
a)
For-profit
b)
Nonprofit
c)
Private company
d)
University
6.
Who can participate in OWASP projects?
a)
Only experts
b)
Only members
c)
Anyone
d)
Only developers
7.
What is the main benefit of the OWASP Top 10?
a)
Reduces performance
b)
Raises awareness of web app risks
c)
Tests hardware
d)
Adds encryption
8.
What is A01:2021 in the OWASP Top 10?
a)
Injection
b)
Broken Access Control
c)
XSS
d)
Security Misconfiguration
9.
What does “Broken Access Control” allow attackers to do?
a)
Modify database schema
b)
Access unauthorized data or accounts
c)
Delete logs
d)
View HTTPS keys
10.
What does A02:2021 “Cryptographic Failures” involve?
a)
Weak encryption or exposure of sensitive data
b)
Weak password policies
c)
Missing logging
d)
Cloud misconfigurations
11.
What replaced “Sensitive Data Exposure”?
a)
Cryptographic Failures
b)
Broken Authentication
c)
Insecure Design
d)
Logging Failures
12.
What does “Injection” refer to?
a)
Entering correct data
b)
Feeding untrusted data that changes program behavior
c)
Logging incorrect passwords
d)
Sending encrypted data
13.
What does A04:2021 “Insecure Design” focus on?
a)
Design flaws and missing threat modeling
b)
SQL syntax
c)
Browser caching
d)
Weak hashing
14.
What is a Security Misconfiguration?
a)
A software bug
b)
A wrong configuration or default password
c)
A slow network
d)
A memory leak
15.
Example of Security Misconfiguration?
a)
Default admin account enabled
b)
TLS 1.3 usage
c)
Hashed passwords
d)
API keys stored in vault
16.
What does “Vulnerable and Outdated Components” mean?
a)
Using old or unpatched dependencies
b)
Missing comments
c)
Long code functions
d)
Complex database schemas
17.
What tool reports known vulnerabilities (CVE)?
a)
Firewall
b)
NVD
c)
API Gateway
d)
Jenkins
18.
What was previously called “Broken Authentication”?
a)
Identification and Authentication Failures
b)
Session Hijacking
c)
Logging Failures
d)
Credential Leakage
19.
What issue results from poor password management?
a)
Injection
b)
Identification & Authentication Failures
c)
Insecure Design
d)
Security Misconfiguration
20.
What is a good countermeasure for Authentication Failures?
a)
Enforce strong passwords & MFA
b)
Disable HTTPS
c)
Use plain text passwords
d)
Disable logs
21.
What are “Software and Data Integrity Failures”?
a)
Using unverified updates or components
b)
Misusing logs
c)
Input validation bugs
d)
Caching issues
22.
Example of Data Integrity Failure?
a)
Using untrusted plugins from unknown sources
b)
Strong encryption
c)
Logging errors
d)
Data masking
23.
What are “Security Logging and Monitoring Failures”?
a)
Failure to record or review important events
b)
Too much log data
c)
Duplicate logs
d)
Wrong file path
24.
Why is logging important for security?
a)
Detecting suspicious activity
b)
Faster runtime
c)
Reducing costs
d)
Improving UX
25.
What is “Server-Side Request Forgery” (SSRF)?
a)
Trick the server into making unintended HTTP requests
b)
Modify session cookies
c)
Capture passwords
d)
Bypass encryption
26.
Why are SSRF attacks increasing?
a)
Due to cloud services and complex architectures
b)
Because HTTP is faster
c)
Due to small apps
d)
Due to slow firewalls
27.
What helps prevent SSRF?
a)
Validating user-supplied URLs
b)
Disabling HTTPS
c)
Using plain text
d)
Ignoring logs
28.
What does OWASP recommend for developers?
a)
Ignore security in design
b)
Integrate security early
c)
Focus only on UI
d)
Delay testing
29.
What is the overall goal of OWASP Top 10?
a)
Improve security awareness and reduce risk
b)
Increase performance
c)
Replace security tools
d)
Build faster UIs
30.
What is a general best practice inspired by OWASP?
a)
Validate inputs and restrict access
b)
Allow all traffic
c)
Disable encryption
d)
Ignore warnings
Reset
