Web Application Security Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Web Application Security flashcards as text
Which OWASP Top 10 category covers broken authentication and session weaknesses?
Answer: Identification and Authentication Failures
Identification and Authentication Failures addresses weak login and session management.
A directory traversal attack uses sequences like ../../ to:
Answer: Access files outside the web root
Path traversal navigates the filesystem to read files outside the intended directory.
Server-Side Request Forgery (SSRF) is dangerous mainly because it can:
Answer: Make the server request internal resources
SSRF tricks the server into requesting internal services or cloud metadata endpoints.
Which Content-Security-Policy directive helps mitigate XSS?
Answer: script-src
The script-src directive restricts which sources can execute scripts, reducing XSS impact.
A web shell uploaded through an unrestricted file upload allows an attacker to:
Answer: Execute commands on the server
A web shell provides remote command execution on the compromised server.
Which flag on a session cookie prevents it from being accessed by JavaScript?
Answer: HttpOnly
The HttpOnly flag blocks JavaScript access, mitigating cookie theft via XSS.
Blind SQL injection is identified primarily by:
Answer: Differences in true/false responses or timing
Blind SQLi infers data from boolean response changes or time delays, without direct output.