HomeSubjectsUniversityBlogAbout

Web Security

Topic in Cyber Security

210 total MCQsShowing 30 with explanations10 Easy10 Medium10 Hard

About This Topic

Web security is the protection of websites, web applications and their users from attacks that exploit HTTP, browsers, sessions and server-side code. OWASP-style vulnerabilities drive most questions: SQL injection including blind variants, stored, reflected and DOM-based XSS, CSRF and its token defence, server-side template injection, SSRF and insecure direct object references. Session handling items ask about cookie flags such as HttpOnly, Secure and SameSite. You should also understand what HTTPS and TLS certificates guarantee, how Content Security Policy and its report-only mode work, the same-origin policy and CORS, and why input validation and output encoding go together.

Below are 30 practice questions from a pool of 210 Web Security MCQs, one of 16 topics in Cyber Security. Each shows the correct answer with an explanation; when you are ready, take a timed quiz to test recall under exam conditions.

Practice Questions

Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.

Web SecurityEasy

Q1. What is a phishing website?

  1. A.A government website providing official public services
  2. B.A secure website verified by a certificate authority
  3. C.A website about recreational fishing techniques and tips
  4. D.A fake website designed to trick users into revealing personal information✓ Correct

Explanation

A phishing website impersonates a legitimate site to deceive users into entering sensitive information.

Report an error in this question

Web SecurityEasy

Q2. Why check for a padlock icon in the browser address bar?

  1. A.It shows the site operates without any advertisements
  2. B.It means the site loads with high-performance speed
  3. C.It means the site is popular and heavily visited
  4. D.It indicates the connection is encrypted with SSL/TLS✓ Correct

Explanation

The padlock icon indicates the website connection is encrypted using SSL/TLS.

Report an error in this question

Web SecurityEasy

Q3. What is the purpose of CAPTCHA on websites?

  1. A.To deliberately slow down website page loading speed
  2. B.To distinguish between human users and automated bots✓ Correct
  3. C.To compress and optimize images for web page loading
  4. D.To encrypt data using symmetric cipher algorithms

Explanation

CAPTCHA verifies that a user is human, preventing automated bot access.

Report an error in this question

Web SecurityEasy

Q4. What is a secure password practice for web accounts?

  1. A.Using the same password everywhere
  2. B.Using single-character passwords
  3. C.Writing passwords on sticky notes
  4. D.Using unique, strong passwords for each website✓ Correct

Explanation

Using unique, strong passwords for each website prevents a breach of one account from compromising others.

Report an error in this question

Web SecurityEasy

Q5. What is a web application firewall (WAF)?

  1. A.A standard web browser used for accessing internet-hosted content
  2. B.An online platform used for creating and hosting web content
  3. C.A physical barrier installed to protect building infrastructure
  4. D.A security solution that filters and monitors HTTP traffic between a web app and the internet✓ Correct

Explanation

A WAF protects web applications by filtering and blocking malicious HTTP/HTTPS traffic.

Report an error in this question

Web SecurityEasy

Q6. What is a cookie in web security?

  1. A.A category of self-replicating malicious software
  2. B.A small piece of data stored by a web browser for session management✓ Correct
  3. C.A baked food snack or treat served at parties
  4. D.A security tool for scanning and detecting vulnerabilities

Explanation

A cookie is a small text file stored by the browser for session management, preferences, and tracking.

Report an error in this question

Web SecurityEasy

Q7. What does HTTPS indicate in a website URL?

  1. A.The website is an older legacy version of the platform
  2. B.The website loads with higher overall speed performance
  3. C.The website is free to access without any subscription
  4. D.The website uses encrypted communication via SSL/TLS✓ Correct

Explanation

HTTPS indicates that the website uses SSL/TLS encryption to secure browser-server communication.

Report an error in this question

Web SecurityMedium

Q8. What is session hijacking?

  1. A.Properly logging out of an active user session across computing environments
  2. B.Creating a new user session for web interaction across computing environments
  3. C.An attack where an attacker takes over a valid user session by stealing the session ID✓ Correct
  4. D.An automated session timeout after inactivity period used in enterprise computing environments

Explanation

Session hijacking involves obtaining a valid session ID to impersonate the legitimate user.

Report an error in this question

Web SecurityEasy

Q9. What is the purpose of two-factor authentication on websites?

  1. A.To deliberately make the login process much slower
  2. B.To completely block all users from accessing the site
  3. C.To add an extra layer of security beyond just a password✓ Correct
  4. D.To encrypt the entire website using a secret algorithm

Explanation

Two-factor authentication adds a second verification step beyond the password.

Report an error in this question

Web SecurityEasy

Q10. What is input validation in web security?

  1. A.Checking keyboard hardware functionality and connectivity
  2. B.Verifying that user-submitted data meets expected criteria before processing✓ Correct
  3. C.Formatting and styling text content on a web page
  4. D.Compressing and reducing the size of input data

Explanation

Input validation checks user-supplied data against expected formats before processing.

Report an error in this question

Web SecurityMedium

Q11. What is the OWASP Top 10?

  1. A.A ranked list of the most widely used web browsers
  2. B.A programming framework for building web app front-ends
  3. C.A curated list of the top ten most popular websites
  4. D.A regularly updated list of the most critical web application security risks✓ Correct

Explanation

The OWASP Top 10 lists the ten most critical web application security risks.

Report an error in this question

Web SecurityMedium

Q12. What is Content Security Policy (CSP)?

  1. A.An HTTP header specifying which content sources are allowed to be loaded by a web page✓ Correct
  2. B.A cascading style sheets framework for responsive page layouts
  3. C.A front-end JavaScript library for dynamic web development
  4. D.A content management system for organizing digital resources

Explanation

CSP allows website operators to control which resources the browser is allowed to load.

Report an error in this question

Web SecurityMedium

Q13. What is Cross-Site Request Forgery (CSRF)?

  1. A.An attack that tricks a browser into making unintended requests to a site where the user is authenticated✓ Correct
  2. B.A form validation technique for checking user inputs within the identity management system
  3. C.A standard type of user login authentication system within the identity management system
  4. D.A type of HTTP cookie used for session tracking within modern computing environments

Explanation

CSRF tricks authenticated users into submitting unwanted requests to a web application.

Report an error in this question

Web SecurityMedium

Q14. What is clickjacking?

  1. A.A software application used for enterprise computing operations
  2. B.A gaming technique for improving response speed used in enterprise computing environments
  3. C.An attack tricking users into clicking hidden elements by layering invisible frames✓ Correct
  4. D.A user account type with specifically assigned access permissions

Explanation

Clickjacking uses transparent layers to trick users into clicking on hidden elements.

Report an error in this question

Web SecurityMedium

Q15. What is SQL injection?

  1. A.An attack that inserts malicious SQL code through user input to manipulate the database✓ Correct
  2. B.A database management system for storing structured records
  3. C.A software application used for enterprise computing operations
  4. D.An optimization technique for improving SQL query speed used in enterprise computing environments

Explanation

SQL injection exploits insufficient input validation to insert malicious SQL statements.

Report an error in this question

Web SecurityMedium

Q16. What is Cross-Site Scripting (XSS)?

  1. A.A responsive web design technique used for structuring and organizing page layouts
  2. B.A front-end JavaScript framework commonly used for building interactive web applications
  3. C.A vulnerability where malicious scripts are injected into trusted websites and executed in browsers✓ Correct
  4. D.A written record or logbook used by teams for tracking daily operational activities

Explanation

XSS allows attackers to inject malicious scripts into web pages viewed by other users.

Report an error in this question

Web SecurityMedium

Q17. What is the Same-Origin Policy?

  1. A.A web browser application for accessing internet-hosted content
  2. B.A security mechanism restricting scripts from one origin from accessing resources of another origin✓ Correct
  3. C.An intellectual property copyright protection law within modern computing environments
  4. D.A common website design pattern for page layout within modern computing environments

Explanation

The Same-Origin Policy restricts web pages from making requests to a different domain, preventing cross-site data theft.

Report an error in this question

Web SecurityEasy

Q18. What does 'session' mean in web security?

  1. A.A formal class held at a school or university within modern computing environments
  2. B.A software application used for enterprise computing operations
  3. C.A period of interaction between a user and a web application, tracked by a session identifier✓ Correct
  4. D.A physical cable used for network connections used in enterprise network infrastructure

Explanation

A web session is a series of interactions tracked using session IDs stored in cookies.

Report an error in this question

Web SecurityMedium

Q19. What is the purpose of HTTP security headers?

  1. A.To format and style web content for visual presentation and management
  2. B.To compress and optimize images for web page loading and management
  3. C.To instruct browsers to enable security features protecting against common web attacks✓ Correct
  4. D.To make websites load faster with better performance and management

Explanation

HTTP security headers instruct browsers to enforce security policies protecting against common attacks.

Report an error in this question

Web SecurityHard

Q20. What is a JSON Web Token (JWT) and its security considerations?

  1. A.A database management system for storing structured records
  2. B.A compact token format for secure claims transfer requiring proper validation and strong algorithms✓ Correct
  3. C.A CSS preprocessor for advanced stylesheet development used in enterprise computing environments
  4. D.A web browser application for accessing internet-hosted content

Explanation

JWT requires proper signature validation, strong algorithms (not none), and protecting the signing key.

Report an error in this question

Web SecurityHard

Q21. What is Server-Side Request Forgery (SSRF)?

  1. A.A type of load balancing technique for traffic distribution used in enterprise computing environments
  2. B.A server performance optimization technique for scaling within modern computing environments
  3. C.An attack that abuses server functionality to make requests to internal resources the attacker cannot directly access✓ Correct
  4. D.A server configuration method for managing network access used in enterprise network infrastructure

Explanation

SSRF exploits server-side functionality to make the server send requests to internal resources.

Report an error in this question

Web SecurityHard

Q22. What is a blind SQL injection attack?

  1. A.A properly secured and parameterized SQL database query for managing enterprise data resources
  2. B.An SQL injection where the attacker infers information by observing application behavior rather than direct output✓ Correct
  3. C.A database backup technique for creating data snapshots for managing enterprise data resources
  4. D.A standard SQL query that returns no data results for managing enterprise data resources

Explanation

Blind SQL injection forces the attacker to infer information through boolean-based or time-based techniques.

Report an error in this question

Web SecurityMedium

Q23. What is the purpose of parameterized queries?

  1. A.To separate SQL code from user data, ensuring input is treated as data not code✓ Correct
  2. B.To compress and reduce the size of database stored data
  3. C.To improve and optimize query execution performance speed
  4. D.To format and style the output of database query results

Explanation

Parameterized queries treat user input strictly as data parameters, preventing SQL injection.

Report an error in this question

Web SecurityHard

Q24. What is insecure deserialization?

  1. A.A database schema problem causing data integrity errors for managing enterprise data resources
  2. B.A vulnerability where untrusted data abuses deserialization logic, potentially leading to remote code execution✓ Correct
  3. C.Slow and inefficient data loading performance issues within enterprise security environments
  4. D.A data format compatibility issue between API versions for managing enterprise data resources

Explanation

Insecure deserialization can allow attackers to execute arbitrary code or escalate privileges.

Report an error in this question

Web SecurityHard

Q25. What is HTTP Request Smuggling?

  1. A.A load balancing technique used for efficiently distributing incoming network traffic
  2. B.A server-side caching mechanism designed for improving web page loading performance
  3. C.A content delivery method used for efficiently distributing static web assets globally
  4. D.An attack exploiting differences in how front-end and back-end servers parse HTTP requests✓ Correct

Explanation

HTTP Request Smuggling exploits inconsistencies in how servers interpret HTTP request boundaries.

Report an error in this question

Web SecurityHard

Q26. What is a race condition vulnerability in web applications?

  1. A.A performance optimization for improving application speed
  2. B.A flaw where concurrent requests exploit timing gaps in security checks✓ Correct
  3. C.A caching problem causing stale data to be served
  4. D.A load balancing issue affecting resource distribution

Explanation

Race conditions in web apps occur when concurrent requests exploit timing gaps between checks and actions.

Report an error in this question

Web SecurityHard

Q27. What is the purpose of Subresource Integrity (SRI)?

  1. A.To improve and optimize page load speed performance and management
  2. B.To compress and minify JavaScript and CSS scripts within enterprise computing infrastructure
  3. C.To allow browsers to verify fetched resources have not been tampered with using cryptographic hashes✓ Correct
  4. D.To organize and manage web page static resources within enterprise computing infrastructure

Explanation

SRI enables browsers to verify that resources from CDNs have not been tampered with.

Report an error in this question

Web SecurityHard

Q28. What is DOM-based XSS?

  1. A.It is identical in behavior to reflected cross-site scripting across computing environments
  2. B.Reflected XSS is exclusively a client-side vulnerability within enterprise security environments
  3. C.DOM-based XSS is a server-side vulnerability entirely within enterprise security environments
  4. D.XSS that executes entirely in the browser by manipulating the DOM, unlike reflected XSS which involves the server✓ Correct

Explanation

DOM-based XSS occurs entirely client-side when JavaScript modifies the DOM using untrusted data.

Report an error in this question

Web SecurityHard

Q29. What is the purpose of OAuth 2.0 in web security?

  1. A.To provide delegated authorization allowing third-party apps limited access without sharing credentials✓ Correct
  2. B.To compress and reduce the size of transmitted web data and management
  3. C.To completely block all unauthorized users from access and management
  4. D.To encrypt all web traffic using symmetric cipher algorithms and management

Explanation

OAuth 2.0 enables third-party applications to obtain limited access to user accounts without exposing credentials.

Report an error in this question

Web SecurityHard

Q30. What is the purpose of the HSTS header?

  1. A.To compress and reduce the size of HTTP request headers
  2. B.To force browsers to only use HTTPS, preventing protocol downgrade attacks✓ Correct
  3. C.To block and prevent all incoming and outgoing traffic
  4. D.To improve and speed up web connection establishment

Explanation

HSTS tells browsers to always use HTTPS, preventing SSL stripping and protocol downgrades.

Report an error in this question

Ready to test yourself on Web Security?

Take a timed quiz drawn from 210+ questions on this topic. No signup required — your progress saves in your browser.

Start Web Security Quiz