Question Bank

3705 approved questions from the community

Which of the following are elements of Public Key Infrastructure (PKI)? (Select all that apply)

HARD
MULTIPLE CHOICE
50s
Web Security
by Mohamed

Which of the following are part of the OWASP Top 10 vulnerabilities? (Select all that apply)

HARD
MULTIPLE CHOICE
50s
Web Security
by Mohamed

Which of the following are important attributes of effective security testing? (Select all that apply)

HARD
MULTIPLE CHOICE
50s
Web Security
by Mohamed

Which of the following are important HTTP security headers? (Select all that apply)

MEDIUM
MULTIPLE CHOICE
45s
Web Security
by Mohamed

Which of the following encryption types are used in SSL/TLS? (Select all that apply)

HARD
MULTIPLE CHOICE
50s
Web Security
by Mohamed

What is the primary countermeasure for network-level session hijacking?

MEDIUM
SINGLE CHOICE
35s
Web Security
by Mohamed

What does TLS stand for?

EASY
SINGLE CHOICE
25s
Web Security
by Mohamed

A valid SSL certificate from a trusted CA guarantees that a website is completely secure and trustworthy.

HARD
TRUE FALSE
30s
Web Security
by Mohamed

Escaping user input is sufficient to prevent all XSS attacks.

MEDIUM
TRUE FALSE
30s
Web Security
by Mohamed

XSS attacks can only steal cookies; they cannot perform other malicious actions.

MEDIUM
TRUE FALSE
25s
Web Security
by Mohamed

Modern browsers can mark HTTP websites as 'Not Secure'.

EASY
TRUE FALSE
20s
Web Security
by Mohamed

How do you check if HSTS is enabled on a website?

HARD
SINGLE CHOICE
40s
Web Security
by Mohamed

What is the basic design principle of OWASP ESAPI?

HARD
SINGLE CHOICE
45s
Web Security
by Mohamed

How can Content Security Policy (CSP) be used against clickjacking?

HARD
SINGLE CHOICE
45s
Web Security
by Mohamed

What is a Bug Bounty program?

HARD
SINGLE CHOICE
35s
Web Security
by Mohamed

SSL (Secure Sockets Layer) is still the recommended protocol for secure web communications.

MEDIUM
TRUE FALSE
25s
Web Security
by Mohamed

Having unique usernames produced with high entropy can prevent session hijacking attacks.

HARD
TRUE FALSE
30s
Web Security
by Mohamed

Penetration testing and vulnerability scanning are essentially the same type of security testing.

HARD
TRUE FALSE
30s
Web Security
by Mohamed

What is the best approach for input validation to prevent security vulnerabilities?

MEDIUM
SINGLE CHOICE
35s
Web Security
by Mohamed

What information can attackers steal using XSS?

MEDIUM
SINGLE CHOICE
35s
Web Security
by Mohamed
PreviousPage 106 of 186Next