Web Exploitation

← all quizzes

Answer all 15 questions, then submit. You need 75% to pass. If you don't pass, the reattempt unlocks after 24 hours.

Q1. Transmitting a session cookie without the Secure flag risks:
Q2. A man-in-the-middle position enables session hijacking by:
Q3. Which tool is listed for web application attacks?
Q4. Host header injection can lead to:
Q5. Which is an OWASP Top 10 2021 risk?
Q6. Which is the strongest signal for detecting a hijacked session?
Q7. What is SQL injection?
Q8. The X-Powered-By header should be removed because it:
Q9. Which is another OWASP Top 10 2021 risk?
Q10. Which HTTP response header helps prevent clickjacking?
Q11. A web application may be accessed directly through:
Q12. The main purpose of a Content-Security-Policy header is to:
Q13. Out-of-band SQL injection uses:
Q14. A backup file such as config.php.bak in the web root is dangerous because:
Q15. Detecting injection often starts with: