NEW
Font size
WorksheetsWeb Application and Browser Security Questions
Total questions: 50
Worksheet time: 38mins
Which of the following is not a component of the Internet infrastructure?
Routers
Browsers
Protocols
Operating Systems
One of the main vulnerabilities of the Internet is:
Low bandwidth
Centralized control
Open protocols
Encrypted data
What is the main difference between HTTP and HTTPS?
HTTPS uses JavaScript, while HTTP does not
HTTP is faster than HTTPS
HTTPS encrypts data using SSL/TLS
HTTP uses port 443
During a recent online shopping experience, Kiara was prompted to verify her identity before completing her purchase. Which of the following is a common method for web authentication that she might have encountered?
DNS lookup
CAPTCHA
Two-factor authentication
URL shortening
A typical three-tier web application architecture includes:
Frontend, Database, Printer
Client, Server, Cloud
Presentation, Logic, Data
HTML, CSS, JavaScript
Which of the following is a rising trend in web attacks?
Disk formatting
SQL Injection
Bluetooth spoofing
BIOS attacks
Aanya is developing a new web application and wants to ensure it is secure from various threats. She is considering different security measures to implement. Which of the following falls under application-level web security?
Firewalls
Input validation
Antivirus software
VPN
What is the primary purpose of a Web Application Firewall?
Speed up webpage loading
Encrypt user data
Detect and block malicious traffic
Monitor user logins
Poor configuration in web applications can lead to:
Faster loading speeds
Better UI
Security vulnerabilities
Reduced server load
Which of the following is a technique used in web hacking?
DHCP
DNS tunnelling
Port mirroring
Cross-Site Scripting (XSS)
While checking her emails, Sanya receives a message that appears to be from her bank, asking her to verify her account information by clicking a link. This situation is an example of:
Physical hacking
Social engineering
Application layer attack
Encryption failure
Why is securing web applications important?
To increase advertisement revenue
To reduce internet usage
To protect sensitive data and prevent breaches
To increase the page loading speed
Web application security focuses on:
Physical hardware
Network ports
Application vulnerabilities like SQLi and XSS
Server room temperature
Online Social Networks (OSNs) are primarily used for:
Coding
Browsing
Social interaction and content sharing
Operating systems
In a bustling online community where people share their thoughts and experiences, one major challenge that the members face is:
High-speed data transfer
Unlimited storage
Privacy and misinformation
Hardware failure
What opportunity does social media provide for businesses?
Weak network security
Data loss
Customer engagement and marketing
Server upgrades
In a bustling online community, Arnav notices that many users are sharing information that seems questionable. He realizes that a major pitfall of online social networks is:
Encryption
Server maintenance
Fake profiles and disinformation
Limited APIs
Which social platform offers an API for developers to fetch data?
Microsoft Word
Photoshop
Skype
Which factor most affects a user's credibility in social systems?
Time spent online
Number of ads clicked
Verified content and engagement history
App version
What is the primary purpose of PGP (Pretty Good Privacy)?
To increase email storage
To compress email attachments
To ensure secure and private email communication
To prevent spam
S/MIME is primarily used to:
Send multimedia messages
Encrypt and digitally sign emails
Block spam emails
Format email in HTML
Which of the following is not a common web authentication method?
Password-based login
Biometric scan
CAPTCHA
Packet sniffing
SQL Injection attacks target which component of a web application?
Server’s file system
Database
RAM
Operating System
Which of the following is an example of an injection flaw?
Memory leak
Cross-Site Scripting
SQL injection
Man-in-the-middle
Which type of bug is most commonly exploited in web applications?
Logical bugs
Syntax errors
Off-by-one errors
Input validation flaws
Siya received an email with an attachment from an unknown sender. After downloading the file, her computer started acting strangely. This situation highlights how malicious code like viruses, worms, and trojans are often spread through:
Encrypted web traffic
Source code repositories
User downloads and email attachments
Captchas
XSS attacks typically aim to:
Deface web pages
Inject code into the database
Steal cookies and session data
Crash the web server
Which type of SQL Injection is easiest to detect and exploit?
Blind SQL Injection
Time-based Injection
Error-based SQL Injection
Boolean-based Injection
Buffer overflow attacks are associated with:
Insufficient memory
Slow server response
Memory corruption
Incorrect database queries
One common result of memory corruption exploits is:
Faster data processing
System crash or unauthorized code execution
Increased memory size
Lower latency
Which of the following improves web browser security?
Disabling HTTPS
Keeping browser and plugins updated
Using public Wi-Fi without VPN
Disabling the firewall
Which of these browser features protects against phishing?
Tab browsing
Private mode
URL filtering and warning mechanisms
Bookmarking
Which protocol is typically used to secure E-Commerce transactions?
HTTP
FTP
HTTPS
UDP
What is the main risk in E-Commerce transactions?
Lack of internet access
Unavailability of products
Financial fraud and identity theft
High website traffic
Which of the following techniques can help secure online payment systems?
Password-only login
Two-factor authentication and encryption
Static HTML forms
Manual cash confirmation
In PGP, the public key is used for:
Encrypting and decrypting the message
Encrypting the message and verifying the signature
Decrypting the message and signing it
Compressing email attachments
Which of the following is true about S/MIME?
It only works with Gmail
It does not support digital signatures
It uses X.509 certificates
It requires manual key exchange
OAuth is primarily used for:
Encrypting databases
Blocking malicious users
Delegated access to APIs without sharing credentials
VPN tunneling
During a busy online shopping event, a hacker manages to take control of a user's session on an e-commerce website. This type of attack is known as:
DNS
HTTP methods
Web session management
CAPTCHA forms
Which of the following vulnerabilities allows attackers to run arbitrary commands in the backend?
HTML Injection
Command Injection
XSS
CSRF
Which of the following vulnerabilities allows attackers to run arbitrary commands in the backend?
HTML Injection
Command Injection
XSS
CSRF
A logic flaw in code may cause:
Unauthorized access
Web page formatting errors
HTTP header leak
Browser crashing
A classic exploit that overwrites memory with attacker-controlled data is known as:
Race condition
Heap spraying
Buffer overflow
Code linting
Which is the most secure payment method for online shopping?
Debit card with CVV only
Payment through open Wi-Fi
Encrypted payment gateway with OTP
Manual bank transfer without verification
Which of the following is a preventive cybersecurity measure?
Restoring backups
Real-time monitoring
Installing patches and updates
Filing complaints after an attack
Which Indian law governs cybercrime and electronic commerce?
IPC 302
Companies Act
IT Act 2000
Cybercrime Prevention Act
What is the purpose of computer forensics?
Speeding up programs
Investigating cyber crimes and recovering evidence
Installing antivirus
Formatting corrupted drives
Penetration testing is done to:
Improve software UI
Test security and find weak points
Format the operating system
Update firewalls
Which of the following helps secure a wireless network?
Using default SSID
Broadcasting network name
Enabling MAC address filtering
Disabling firewalls
What is the most secure encryption standard for wireless networks?
WEP
WPA
WPA2
WPA3
