Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

DevOps and Security Quiz

Total questions: 67

Worksheet time: 34mins

Name
Class
Date
1.

Why is it important to keep development, staging, and production environments as close as possible?

a)

Using completely different tools in each environment improves testing coverage.

b)

Allowing major differences in OS, tooling, and configurations between environments ensures flexibility but may introduce subtle bugs and deployment failures.

c)

Minimizing differences reduces environment-specific bugs and increases confidence in deployments.

d)

Large time gaps between environments help identify hidden production issues.

2.

Which statement best explains what an injection attack is in web applications?

a)

It occurs when untrusted input becomes mixed with trusted data and alters how a query or command is interpreted.

b)

It arises when validated data interacts with browser elements and unexpectedly shifts structural page logic.

c)

It emerges when mismanaged request information blends with system routines and affects internal processing workflows in unpredictable ways.

d)

It appears when formatted parameters collide with components and generate unintended operational outcomes.

3.

What is the main purpose of root-cause analysis and incident management in a DevOps team according to the text?

a)

To separate development and operations completely, leaving incident resolution to dedicated operations teams.

b)

To rely solely on external notifications from users or dependencies to detect system failures.

c)

To implement a comprehensive system of logging, monitoring, fire drills, and alerts while also tracking every minor change, user action, and dependency interaction to fully automate incident prevention.

d)

To resolve incidents quickly, document actions, and identify underlying causes to prevent future occurrences.

4.

What is the role of infrastructure in a DevOps environment?

a)

Infrastructure only refers to physical servers that developers must manually configure.

b)

Infrastructure provides computing resources, networking, and services that allow applications to run and scale reliably.

c)

Infrastructure is limited to third-party cloud services, and private servers or custom networking configurations cannot be managed or automated by developers in a DevOps setup.

d)

Infrastructure is solely the responsibility of sysadmins and not the development team.

5.

What does the DREAD model help security professionals do?

a)

Define the architecture of a system and its interface contracts for distributed components.

b)

Assess and prioritize risks based on factors like damage potential, reproducibility, exploitability, affected users, and discoverability.

c)

Implement a comprehensive system of logging, monitoring, and alerts for security incidents.

d)

Focus solely on identifying vulnerabilities in third-party software components.

6.

What is the recommended approach to handle data storage in an application to avoid multiple components introducing inconsistent rules and data?

a)

Store all state in memory within the application tier for faster access and simplicity.

b)

Allow each application service to access the database directly to ensure flexibility in data handling.

c)

Encapsulate the data store behind a dedicated service that implements validation and exposes a consistent API.

d)

Avoid any kind of validation or business logic and rely solely on external scripts for data correctness.

7.

What is a key advantage of using WebSockets over long polling in web applications?

a)

WebSockets automatically cache all server responses to reduce network traffic.

b)

WebSockets guarantee message delivery even if the client loses connection temporarily.

c)

WebSockets eliminate the need for API authentication by using server trust.

d)

WebSockets allow two-way communication without creating a new connection for each message.

8.

Why should developers avoid assigning positive (non-zero) tabindex values when managing keyboard navigation?

a)

It disables default focus behavior so custom JavaScript handlers must replace it.

b)

It prevents screen readers from detecting dynamic updates triggered by scripted UI changes.

c)

It guarantees that AT tools skip elements automatically regardless of their position.

d)

It can create inconsistent navigation order that breaks alignment between visual flow and DOM structure.

9.

According to the text, what is a key practice for effective monitoring and logging in a production system?

a)

Automatically fix errors as they occur, without the need to log or monitor metrics for incidents.

b)

Collect all logs together without separation, relying on post-incident review to find relevant errors when needed.

c)

Store every possible piece of data, including sensitive information, in a single log, and aggregate all metrics regardless of relevance, to ensure complete historical records for any analysis.

d)

Separate logs by concern, capture sufficient context for errors, and set meaningful metrics and alerts to detect issues early.

10.

What is the main purpose of using tools like Vagrant or containers for development environments?

a)

They allow developers to create reproducible environments that match production as closely as possible.

b)

Containers and Vagrant can replace all infrastructure management, including firewalls, scaling, and more.

c)

Developers must manually install all dependencies on each machine for consistency.

d)

They eliminate the need for any deployment scripts or automation entirely.

e)

They are intended to run production workloads directly without configuration changes.

11.

Why is it important to integrate security into the design and development of web applications?

a)

Because adding security only at the end of development ensures all vulnerabilities are automatically fixed.

b)

Because using complex passwords alone guarantees that the system cannot be compromised in any way.

c)

Because outsourcing all security responsibilities to external tools eliminates the need for developer involvement.

d)

Because relying solely on security by obscurity or a single layer of protection provides comprehensive defense against all possible attacks.

e)

Because a system is only as secure as its weakest point, requiring careful planning to prevent unauthorized access.

12.

What is the primary purpose of monitoring in a DevOps environment?

a)

To rely on users reporting issues, such as social media posts, as the main indicator of system problems.

b)

To track every technical detail, including all logs, metrics, and user interactions, for exhaustive analysis, even if it doesn’t immediately prevent outages.

c)

To collect large amounts of data primarily for post-mortem analysis without providing real-time alerts.

d)

To detect potential problems early through metrics and logs, allowing the team to respond before users are affected.

e)

To replace the need for on-call staff by automatically fixing incidents without human intervention.

13.

Why is it generally recommended to use elements instead of for actions in web apps?

a)

Triggers background scripts that conflict with ARIA (Accessible Rich Internet Applications) attributes by default.

b)

Correctly conveys action semantics to assistive technologies, improving accessibility.

c)

Forces screen readers to ignore all nearby links, simplifying navigation.

d)

Tags are deprecated in HTML and cannot be styled consistently across browsers.

e)

Automatically disables all keyboard navigation conflicts on complex pages.

14.

Why are database migrations important in application development?

a)

They permanently lock the database schema so no changes can be made in the future.

b)

They allow developers to apply incremental changes to the database schema in a controlled manner.

c)

They automatically generate all database queries without developer input.

d)

They ensure that all database operations are performed in-memory for faster execution.

15.

What is the main difference between continuous delivery and continuous deployment?

a)

Continuous deployment avoids using pipelines or CI/CD tools, and instead requires developers to manually copy code to production after each commit.

b)

Continuous deployment only prepares code for release but requires manual deployment.

c)

Continuous delivery ensures changes are ready for release, while continuous deployment automatically releases every change to production.

d)

Continuous delivery ignores automation and relies on manual testing for every release.

16.

Why should on-call teams rely on well-maintained runbooks?

a)

Because runbooks reduce the need for logs in diagnosing failures.

b)

Because runbooks eliminate the need for domain knowledge entirely.

c)

Because runbooks provide clear steps for resolving known classes of incidents.

d)

Because runbooks automatically sync across all deployed regions.

17.

Why must environment-specific configuration never be stored in code?

a)

Because configuration rarely changes, so storing it in code has no effect.

b)

Because code-based config loads faster on multi-core processors.

c)

Because embedding configuration risks exposing sensitive data and limits portability.

d)

Because environment variables reduce browser request sizes.

18.

Why should accessible components avoid relying solely on hover-based interactions?

a)

Because hover states load additional fonts that reduce UI performance.

b)

Because hover actions exclude users on touch devices and keyboard-only navigation.

c)

Because hover effects require high refresh-rate displays to function correctly.

d)

Because hover styling always increases layout shift during rendering.

19.

Why is versioning important when evolving an API over time?

a)

Because versioning eliminates the need for load balancing in microservices.

b)

Because version numbers dictate server memory allocation policies.

c)

Because versioning allows changes without breaking existing client integrations.

d)

Because API upgrades automatically propagate when no version is defined.

20.

Why must alerts remain actionable rather than overly noisy?

a)

Because alerts should always fire regardless of severity.

b)

Because alert systems function best when thresholds are never adjusted.

c)

Because actionable alerts let engineers focus on real issues instead of filtering distractions.

d)

Because alert-triggered events block focus indicators from appearing.

21.

Why is output encoding effective at preventing XSS attacks?

a)

Because encoding neutralizes script injection by treating malicious input as text

b)

Because encoded values increase CPU load making attacks harder

c)

Because encoded output disables caching for security-related content

d)

Because encoding forces browsers to ignore all client-side logic

e)

Because encoding blocks all inline styling from loading on the page

22.

Why are foreign key constraints crucial in relational systems?

a)

Because relational databases require no validation when constraints are absent

b)

Because foreign keys reduce application logic and remove the need for caching

c)

Because constraints only exist to reduce physical disk usage

d)

Because foreign keys improve UI responsiveness in large dashboards

e)

Because they prevent inconsistent relationships and maintain data integrity

23.

What is the main purpose of using a "screen-reader-only" technique such as the modern .sr-only CSS class?

a)

It converts icons into captions so graphical elements behave like full text labels

b)

It forces browsers to replace background images with readable labels automatically

c)

It blocks hidden text from search engines to avoid duplicate semantic information

d)

It removes text entirely so visual layouts remain cleaner for all device categories

e)

It hides text visually while keeping it accessible to assistive tools that rely on the DOM

24.

What is the primary purpose of programmatically restoring focus after an interactive element is removed from the DOM?

a)

It converts all removed components into static content visible only to assistive tools

b)

It forces screen readers to re-announce all page regions regardless of user context

c)

It disables default navigation so custom keyboard shortcuts replace the tab sequence

d)

It prevents unexpected focus loss that would otherwise send keyboard users back to the top of the page

e)

It refreshes the DOM tree to ensure hidden elements are permanently discarded

25.

What is the main purpose of salting a password hash in web applications?

a)

To create a visually complex password that contains numbers, symbols, and capital letters automatically

b)

To store a backup copy of the original password in a separate database for verification purposes

c)

To combine multiple passwords together so that users must enter several secrets at login

d)

To add a unique random value to each password hash, making dictionary attacks and hash collisions more difficult

e)

To strengthen password security by appending a secret and unique random string to each hash, slowing attackers and preventing reuse of identical hashes across accounts

26.

It is important to consider deployment early in the web application development process because:

a)

it helps identify potential deployment challenges and ensures a smoother launch.

b)

it allows developers to skip testing phases.

c)

it eliminates the need for version control.

d)

it guarantees that no bugs will occur after release.

27.

Why is it important for developers to consider deployment constraints during application design?

a)

Because ignoring deployment considerations can not lead to scalability, storage, and operational issues that will not impact the application's stability and user experience.

b)

Because deployment constraints can affect design decisions like session storage and file handling.

c)

Because deployment only matters after the application is fully built and tested.

d)

Because developers do not need to understand the environment their app will run in.

e)

Because continuous delivery and DevOps are only relevant for large-scale enterprise projects.

28.

What is the main advantage of using REST over SOAP (Simple Object Access Protocol) for web APIs?

a)

REST can only be used with XML, limiting the formats supported for responses.

b)

REST requires strict schemas and additional tools for request formatting and debugging.

c)

REST does not support caching or stateless interactions, which SOAP handles automatically.

d)

REST reuses standard HTTP mechanisms, making requests simpler without special libraries.

e)

REST mandates a single URL endpoint for all API requests regardless of resource type.

29.

What is the recommended way to handle secrets like API keys or passwords in a web application?

a)

Keep them separate from source code, restrict access to a need-to-know basis, and rotate them regularly.

b)

Embed them directly in the source code to make deployment easier and reduce configuration steps.

c)

Share secrets freely among all developers so anyone can debug or deploy without restriction.

d)

Use hidden URLs and obscure names for sensitive endpoints to ensure attackers cannot guess them.

e)

Store them in plain text on public repositories to allow easy access for automated scripts.

30.

When designing an API, which of the following is the most recommended approach for handling client errors such as invalid requests?

a)

Always redirect the user to the home page without explanation.

b)

Display a plain text message in the browser console only.

c)

Return a structured JSON error message detailing the validation issues.

d)

Send the full server stack trace in the HTTP response for debugging.

e)

Ignore the error and attempt to process the request anyway.

31.

What is a key benefit of applying DevOps practices with automation and feature flags?

a)

Teams must deploy all changes manually to ensure safety and accuracy.

b)

Automation eliminates the need for any configuration or environment management.

c)

Feature flags allow changes to be deployed without testing or control.

d)

Using DevOps automation forces all teams to use the same infrastructure, tools, and deployment schedule, regardless of project requirements or constraints.

e)

Teams can deploy smaller, more frequent changes, reducing risk and speeding up delivery.

32.

What is a key consideration when introducing dependencies or libraries into a web application?

a)

Security is not important for front-end dependencies, so they can be added without review.

b)

Only major libraries need auditing, as smaller or nested dependencies rarely contain vulnerabilities.

c)

Introducing new dependencies without assessing their maintenance, community support, or update history can increase the likelihood of security breaches in your system.

d)

You can assume all libraries are secure if they come from popular public repositories without additional checks.

e)

You should assess their security impact, maintain updates, and verify that they are actively maintained.

33.

What is the main principle of immutable infrastructure in DevOps?

a)

Updates to infrastructure are made incrementally on the live environment to avoid downtime, rather than replacing it entirely with a fresh deployment.

b)

Immutable infrastructure applies only to test environments, not production systems.

c)

Only the code changes, while the underlying infrastructure is modified in place.

d)

Infrastructure should be manually tweaked after deployment to fix minor issues.

e)

Once deployed, infrastructure and code are never changed; updates are made by replacing components with new versions.

34.

Why should error responses in APIs follow a predictable structure?

a)

Because consistent formatting helps clients handle issues programmatically.

b)

Because structured errors eliminate the need for API versioning entirely.

c)

Because predictable structures reduce storage cost for archived logs.

d)

Because error formats directly affect database indexing and search speed.

e)

Because varied error formats improve logging diversity across environments.

35.

Why should logs be collected as continuous event streams?

a)

Because streaming logs enable centralized aggregation and real-time monitoring.

b)

Because event streams automatically compress themselves without storage cost.

c)

Because page rendering depends directly on streaming log throughput.

d)

Because log streaming replaces the need for alerting systems entirely.

e)

Because streaming guarantees that logs contain no duplicate entries.

36.

Why are blameless post-mortems recommended after incidents?

a)

Because assigning blame helps identify which team needs fewer engineers.

b)

Because incident reviews must primarily focus on rewriting user documentation.

c)

Because they encourage honest analysis focused on systemic improvement.

d)

Because post-mortems should measure UI satisfaction rather than root causes.

e)

Because the goal of incident analysis is to reduce monitoring alerts.

37.

Why is proactive monitoring vital for production reliability?

a)

Because high-volume traffic negates the need for alerting.

b)

Because monitoring reveals early signs of failure before they affect users.

c)

Because monitoring tools require user action to trigger events.

d)

Because metrics remain accurate only when monitoring is disabled.

38.

Why must database schemas be designed with future scalability in mind?

a)

Because relational constraints reduce performance under all conditions

b)

Because scalable schema models eliminate the need for indexes

c)

Because unplanned schemas work fine as long as queries remain simple

d)

Because schemas automatically rebuild themselves when structures degrade

e)

Because poor schema design becomes expensive to correct as data volume grows

39.

Why use HTTPS for all production traffic, even for non-sensitive endpoints?

a)

Because encrypted traffic disables caching to improve data freshness

b)

Because HTTPS forces clients to refresh tokens after every request

c)

Because HTTPS removes latency associated with round-trip communication

d)

Because TLS automatically compresses payloads for faster delivery

e)

Because encrypted transport prevents manipulation or inspection of any transmitted data

40.

Why should passwords be hashed rather than encrypted with a reversible method?

a)

Because encrypted passwords automatically expire after a session

b)

Because encrypted passwords synchronize more slowly across servers

c)

Because hashing requires fewer code changes during deployments

d)

Because hashing makes stolen password data unusable to attackers

e)

Because hashing allows faster authentication under heavy traffic

41.

Why is capacity planning essential before peak traffic events?

a)

Because peak traffic reduces required memory usage

b)

Because capacity increases only when endpoints return HTTP 500

c)

Because planning ensures the system can handle expected load without degradation

d)

Because hardware adds capacity automatically during downtime

e)

Because unplanned scaling always leads to faster response times

42.

Why is immutable infrastructure more reliable than mutable servers?

a)

Because immutability forces all apps to use the same database schema

b)

Because immutable servers replace the need for application logging

c)

Because immutable hosts automatically upgrade dependencies

d)

Because mutability only affects frontend caches, not backends

e)

Because immutability eliminates configuration drift between deployments

43.

Why should session tokens be rotated periodically?

a)

Because token rotation is needed only when the UI theme changes

b)

Because token rotation ensures faster garbage collection in memory

c)

Because rotation limits the usefulness of a compromised token

d)

Because session tokens degrade visually when reused too often

e)

Because rotating tokens increases the accuracy of analytics tracking

44.

What is the main difference between a key-value store and a document store in NoSQL databases?

a)

A key-value store is always distributed across multiple machines, whereas a document store must run on a single server.

b)

A key-value store retrieves data only by a unique key, while a document store allows queries based on the content inside the document.

c)

A key-value store stores data in tables with rows and columns, while a document store stores all data as plain text files.

d)

A key-value store is optimized for graph traversal, while a document store only allows sequential reads.

45.

What is the primary purpose of using ARIA (Accessible Rich Internet Applications) roles when standard HTML elements cannot express the required behavior or structure?

a)

They guarantee that all dynamic UI updates are announced visually without requiring additional logic.

b)

They replace the need for keyboard-friendly interaction patterns by simulating default browser controls.

c)

They provide assistive technologies with semantic meaning that native HTML cannot convey in complex custom components.

d)

They allow developers to bypass semantic HTML so all elements can be freely styled as plain containers.

46.

Which HTTP status code indicates that a request has succeeded and the server has returned the expected response?

a)

400 Bad Request indicates that the request was invalid or could not be processed properly.

b)

200 OK indicates the request was successful and the response contains the expected data.

c)

404 Not Found indicates the requested resource could not be located on the server.

d)

302 Found indicates a temporary redirection to another URL for the requested resource.

47.

What is the main principle of executing an app as one or more stateless processes?

a)

The app should keep session data in memory for faster response times.

b)

Each script should terminate without using a backing store for files.

c)

State can be stored locally if the server has sufficient memory capacity.

d)

The app must not store state locally and rely on an attached backing store for data.

48.

According to the text, what is a key practice for effective monitoring and logging in a production system?

a)

Focus only on business KPIs and analytics.

b)

Automatically fix errors without logging.

c)

Ensure logs are comprehensive and actionable.

d)

Avoid logging to reduce system overhead.

49.

What is the main difference between continuous delivery and continuous deployment?

a)

Continuous delivery automatically deploys all changes to production.

b)

Continuous deployment avoids CI/CD tools.

c)

Continuous delivery ignores automation.

d)

Continuous delivery prepares changes for release, while continuous deployment releases automatically.

e)

Continuous deployment only prepares code for release.

50.

Why is it important to integrate security into the design and development of web applications?

a)

Because a system is only as secure as its weakest point, requiring careful planning to prevent unauthorized access.

b)

Because using complex passwords alone guarantees that the system cannot be compromised in any way.

c)

Because relying solely on security by obscurity or a single layer of protection provides comprehensive defense against all possible attacks.

d)

Because outsourcing all security responsibilities to external tools eliminates the need for developer involvement.

e)

Because adding security only at the end of development ensures all vulnerabilities are automatically fixed.

51.

According to the text, what is a key practice for effective monitoring and logging in a production system?

a)

Focus only on business KPIs and analytics, ignoring technical metrics and system health monitoring.

b)

Automatically fix errors as they occur, without the need to log or monitor metrics for incidents.

c)

Separate logs by concern, capture sufficient context for errors, and set meaningful metrics and alerts to detect issues early.

d)

Store every possible piece of data, including sensitive information, in a single log, and aggregate all metrics regardless of relevance, to ensure complete historical records for any analysis.

e)

Collect all logs together without separation, relying on post-incident review to find relevant errors when needed.

52.

What is the main difference between continuous delivery and continuous deployment?

a)

Continuous delivery automatically deploys all changes to production without any checks.

b)

Continuous deployment avoids using pipelines or CI/CD tools, and instead requires developers to manually copy code to production after each commit.

c)

Continuous delivery ignores automation and relies on manual testing for every release.

d)

Continuous delivery ensures changes are ready for release, while continuous deployment automatically releases every change to production.

e)

Continuous deployment only prepares code for release but requires manual deployment.

53.

According to the text, what is a key element of an effective run book for handling incidents?

a)

It should contain every possible technical detail about the system, historical logs, code references, and organizational changes, even if irrelevant for immediate incident response.

b)

It only needs to include general advice and high-level guidance, leaving responders to figure out exact steps.

c)

It primarily lists previous incidents without including specific steps or contacts for resolving new issues.

d)

It should provide detailed step-by-step procedures, contact paths, and escalation instructions so responders can act correctly under pressure.

54.

Why is semantic HTML important when building pages that work well with assistive technologies?

a)

It replaces the need for progressive enhancement because scripts handle all accessibility.

b)

It forces every component to use ARIA roles even when native semantics already exist.

c)

It preserves meaningful structure that assistive technologies can interpret correctly without relying on visual styling.

d)

It ensures automated SEO tools apply fixed rankings regardless of content hierarchy.

55.

Why should a twelve-factor app expose its services by port binding?

a)

Using local files instead of network ports simplifies scaling, deployment, and independent process management across multiple servers.

b)

Exposing interfaces via UNIX sockets is preferred for network scalability.

c)

Port binding is unnecessary if all services run on the same server.

d)

Communication should occur over the network, allowing services to run on separate machines.

56.

Why is it recommended to perform sanitization at the edge of a system?

a)

To avoid validation and rely solely on trusted internal data handling mechanisms.

b)

To ensure that users can inject any HTML or JSON content without limitations.

c)

To make the system faster by skipping checks on external inputs in other modules.

d)

To ensure data leaving or entering the system is safe and reduces risks of corruption.

57.

Why should developers avoid assigning positive (non-zero) tabindex values when managing keyboard navigation?

a)

It can create inconsistent navigation order that breaks alignment between visual flow and DOM structure.

b)

It prevents screen readers from detecting dynamic updates triggered by scripted UI changes.

c)

It disables default focus behavior so custom JavaScript handlers must replace it.

d)

It ensures automated SEO tools apply fixed rankings regardless of content hierarchy.

58.

What is considered the "golden rule" when handling user input in web applications?

a)

Validate only administrative input while skipping normal users' data checks

b)

Always log user input without validation to ensure comprehensive auditing

c)

Never validate input and rely solely on firewall protection against attacks

d)

Validate input from users and sanitize output before displaying it

59.

According to the provided material, what is the primary reason the Build, Release, Run phases must remain strictly separated in an application's deployment process?

a)

Keeping these phases separate prevents developers from tagging commits in version control, ensuring that configuration is always rebuilt dynamically whenever the service restarts.

b)

Following this separation model ensures that all configuration changes automatically rebuild the source code, keeping every deployment perfectly synchronized with production edits.

c)

Separating build, release, and run ensures consistent, traceable deployments, enables predictable rollbacks, and prevents runtime failures caused by missing dependencies or on-the-fly asset compilation.

d)

Distinct deployment phases are required because modern frameworks mandate performing all asset transformations during execution, ensuring runtime updates occur faster than prebuilt release bundles.

60.

What is the main advantage of using REST over SOAP (Simple Object Access Protocol) for web APIs?

a)

REST does not support caching or stateless interactions, which SOAP handles automatically.

b)

REST can only be used with XML, limiting the formats supported for responses.

c)

REST mandates a single URL endpoint for all API requests regardless of resource type.

d)

REST reuses standard HTTP mechanisms, making requests simpler without special libraries.

61.

Why must alerts remain actionable rather than overly noisy?

a)

Because alert systems function best when thresholds are never adjusted

b)

Because alerts should always fire regardless of severity

c)

Because noisy alerts improve response accuracy by overwhelming the team

d)

Because actionable alerts let engineers focus on real issues instead of filtering distractions

62.

Why are blameless post-mortems recommended after incidents?

a)

To ensure accountability is assigned to specific individuals

b)

To identify and punish the root cause of the incident

c)

To foster a culture of learning and improvement without fear of blame

d)

To document incidents for legal purposes

63.

Why must incident reviews primarily focus on systemic improvement?

a)

Because incident reviews must primarily focus on rewriting user documentation

b)

Because they encourage honest analysis focused on systemic improvement

c)

Because post-mortems should measure UI satisfaction rather than root causes

d)

Because assigning blame helps identify which team needs fewer engineers

64.

Why must environment-specific configuration never be stored in code?

a)

Because environment config makes deployment pipelines optional

b)

Because code-based config loads faster on multi-core processors

c)

Because configuration rarely changes, so storing it in code has no effect

d)

Because embedding configuration risks exposing sensitive data and limits portability

65.

Why should logs be collected as continuous event streams?

a)

Because streaming guarantees that logs contain no duplicate entries

b)

Because page rendering depends directly on streaming log throughput

c)

Because event streams automatically compress themselves without storage cost

d)

Because streaming logs enable centralized aggregation and real-time monitoring

66.

Why should session tokens be rotated periodically?

a)

Because token rotation is needed only when the UI theme changes

b)

Because token rotation ensures faster garbage collection in memory

c)

Because session tokens degrade visually when reused too often

d)

Because rotation limits the usefulness of a compromised token

67.

Why should passwords be hashed rather than encrypted with a reversible method?

a)

Because hashing requires fewer code changes during deployments

b)

Because hashing allows faster authentication under heavy traffic

c)

Because encrypted passwords automatically expire after a session

d)

Because hashing makes stolen password data unusable to attackers