Crest Flashcards
7 cards from real CPSA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Crest flashcards as text
What is the primary defense against Cross-Site Request Forgery (CSRF) attacks in web applications?
Answer: Synchronizer token pattern using unpredictable CSRF tokens
Anti-CSRF tokens are unique, unpredictable values tied to user sessions that must be submitted with each state-changing request, preventing forged requests.
Which HTTP response header instructs browsers to prevent MIME-type sniffing, reducing XSS risk from uploaded files?
Answer: X-Content-Type-Options
X-Content-Type-Options: nosniff prevents browsers from interpreting files as a different MIME type than declared, mitigating attacks via content-type confusion.
During a web application test, you find that changing the order ID in a URL reveals another user's order. What vulnerability is this?
Answer: Insecure Direct Object Reference (IDOR)
IDOR occurs when an application uses user-controlled input to access objects directly without verifying the requesting user's authorization.
What does a Blind SQL injection vulnerability differ from a classic SQL injection in terms of exploitation?
Answer: Blind SQLi does not return query results directly; data is inferred from application behavior
In blind SQL injection, the attacker cannot see query output directly and must infer information from differences in application responses or timing.
Which encoding technique is most effective at preventing reflected XSS when inserting user input into HTML content?
Answer: HTML entity encoding
HTML entity encoding converts characters like , and & into their HTML entities, preventing browsers from interpreting injected content as executable markup.
What is the security risk of storing sensitive data in the browser's localStorage?
Answer: Data persists after browser close and is accessible to any JavaScript on the origin
localStorage data has no expiry, persists across sessions, and is accessible to any JavaScript running on the same origin, making XSS attacks able to exfiltrate sensitive tokens.
When testing for Server-Side Template Injection (SSTI), which payload is commonly used to identify a vulnerable endpoint?
Answer: {{7*7}}
Submitting {{7*7}} tests whether a template engine evaluates the expression; if the response contains 49, the input is being processed as a template.