WorksheetsWeb Sys Day 3
Total questions: 10
Worksheet time: 3mins
Which statement best describes a web cookie?
A small text file stored by websites
A server-side session variable only
An executable program installed by apps
A cloud database shared across sites
A cookie with name session_id and value 17cbad3fd19 most likely serves which purpose?
Caches large media resources
Tracks number of visits count
Saves color preference setting
Identifies a logged-in user
Which is a common use of cookies on e-commerce sites?
Host the entire product catalog
Render 3D product animations
Encrypt all payment transactions
Track items in your shopping cart
Which statement best defines a web session in user authentication?
A temporary state starting at login and ending on logout
A browser file that permanently stores all user details
A background process that runs even without user login
A network connection that persists after closing the browser
A website needs to remember a logged-in user across pages. Which mechanism correctly describes this process?
Browser caches full profile data and replays it on navigation
Browser stores session ID in a cookie and sends it on each request
Server embeds username into page HTML for later recovery
Server stores the password in a cookie and reads it every time
After successful login, which item is most appropriately stored inside the cookie to maintain login state?
Random session ID linking to server-side data
Encrypted password for quick verification
User’s full profile including preferences
Plaintext username and visit counter
Which option best captures the session analogy described: a session is most like a visitor pass because it primarily does what?
Displays your full identity details to everyone
Grants unlimited access without verification steps
Signals to security that you are authorized to be present
Stores personal information permanently on the badge
In an OAuth 2.0 login, what is the role of the access token?
It stores the user's plaintext password
It grants limited access on behalf of the user
It resets the user's credentials remotely
It creates a new user account automatically
Why do websites offer buttons like "Log in with Google"?
To bypass identity verification entirely
To avoid creating any user sessions at all
To leverage OAuth for delegated authorization
To force users to share passwords with apps
In the illustrated flow, who verifies the user's identity before issuing an access token?
The identity provider such as Google
The browser extension
The application itself
The local database on the device
