Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.
Web SecurityEasy
Q1. What is HTTPS?
- A.HTTP with encryption using TLS/SSL for security✓ Correct
- B.A database protocol for encrypted connections
- C.A faster version of HTTP for static content
- D.A programming language for server applications
Explanation
HTTPS encrypts data between browser and server using TLS/SSL.
Report an error in this question
Web SecurityEasy
Q2. What is a password hash?
- A.A one-way transformation into a fixed-length string✓ Correct
- B.A password hint for helping users remember
- C.A password reset link sent via email notification
- D.An encrypted password stored with a cipher key
Explanation
Hashing converts passwords into irreversible fixed-length strings.
Report an error in this question
Web SecurityEasy
Q3. What is XSS (Cross-Site Scripting)?
- A.A JavaScript framework for building secure apps
- B.A CSS extension for adding custom properties
- C.A vulnerability where malicious scripts are injected✓ Correct
- D.A database attack targeting stored procedures
Explanation
XSS attacks inject malicious scripts into web pages viewed by other users.
Report an error in this question
Web SecurityEasy
Q4. What is a firewall?
- A.A NoSQL database for storing security records
- B.A JavaScript library for client-side validation
- C.A CSS border property for styling elements
- D.A system monitoring and controlling network traffic✓ Correct
Explanation
A firewall filters network traffic based on security rules.
Report an error in this question
Web SecurityEasy
Q5. What is authentication?
- A.A JavaScript function for data validation
- B.The process of verifying a user's identity✓ Correct
- C.A CSS technique for styling form elements
- D.Authorizing access to protected resources
Explanation
Authentication verifies who a user is.
Report an error in this question
Web SecurityEasy
Q6. What is a cookie in web security?
- A.A CSS property for styling decorated elements
- B.A small data piece stored for session management✓ Correct
- C.A browser game for entertainment purposes
- D.A JavaScript variable stored in local memory
Explanation
Cookies are small data files stored by the browser.
Report an error in this question
Web SecurityEasy
Q7. What does SSL stand for?
- A.Secure Socket Layer✓ Correct
- B.Simple Security Layer
- C.Secure Server Link
- D.Server Side Logic
Explanation
SSL stands for Secure Sockets Layer.
Report an error in this question
Web SecurityEasy
Q8. What is a CAPTCHA?
- A.A test distinguishing humans from automated bots✓ Correct
- B.A type of database for storing user accounts
- C.A JavaScript function for validating form data
- D.A CSS framework for building secure page layouts
Explanation
CAPTCHA verifies that a user is human and not an automated bot.
Report an error in this question
Web SecurityEasy
Q9. What is two-factor authentication (2FA)?
- A.Using two passwords for login authentication
- B.Using two browsers for testing compatibility
- C.Having two accounts for backup and recovery
- D.A method requiring two forms of identification✓ Correct
Explanation
2FA requires two different verification methods for additional security.
Report an error in this question
Web SecurityEasy
Q10. Why should user input be validated?
- A.To improve SEO ranking in search engine results
- B.To improve CSS styling across different browsers
- C.To speed up the database query execution time
- D.To prevent malicious data and protect against attacks✓ Correct
Explanation
Input validation ensures user-supplied data is safe and properly formatted.
Report an error in this question
Web SecurityMedium
Q11. What is CSRF (Cross-Site Request Forgery)?
- A.An attack tricking users into actions on authenticated sites✓ Correct
- B.A CSS framework for building styled web components
- C.A JavaScript error caused by invalid syntax in code
- D.A database attack targeting table join vulnerabilities
Explanation
CSRF exploits an authenticated session to make unauthorized requests.
Report an error in this question
Web SecurityMedium
Q12. How is CSRF typically prevented?
- A.Disabling JavaScript execution in the browser
- B.Using anti-CSRF tokens to verify request origin✓ Correct
- C.Using CSS styles to hide form submission buttons
- D.Using longer and more complex user passwords
Explanation
Anti-CSRF tokens verify that requests originate from the legitimate site.
Report an error in this question
Web SecurityMedium
Q13. What is Content Security Policy (CSP)?
- A.A database policy for query execution permissions
- B.A JavaScript policy for variable access control
- C.A CSS policy for restricting style inheritance
- D.An HTTP header restricting which resources load✓ Correct
Explanation
CSP restricts which resources a page can load, mitigating XSS attacks.
Report an error in this question
Web SecurityMedium
Q14. What is JWT (JSON Web Token)?
- A.A database token for authenticating query access
- B.A compact self-contained token for secure data transfer✓ Correct
- C.A CSS token for custom property values
- D.A JavaScript variable for storing session data
Explanation
JWT is a signed token containing claims used for stateless authentication.
Report an error in this question
Web SecurityMedium
Q15. What is the principle of least privilege?
- A.Disabling all non-essential application features
- B.Giving admin access to every application user
- C.Granting users only the minimum needed permissions✓ Correct
- D.Using the simplest possible password for accounts
Explanation
Least privilege limits permissions to the bare minimum required.
Report an error in this question
Web SecurityMedium
Q16. What is input sanitization?
- A.Compressing HTML to reduce the total page size
- B.Formatting JSON data for consistent key ordering
- C.Removing or encoding dangerous characters from input✓ Correct
- D.Cleaning CSS code by removing unused selectors
Explanation
Sanitization cleans user input by removing or encoding special characters.
Report an error in this question
Web SecurityMedium
Q17. What is CORS and why is it a security concern?
- A.A JavaScript library for making HTTP request calls
- B.Cross-Origin Resource Sharing; misconfiguration exposes data✓ Correct
- C.A CSS framework for cross-browser styling consistency
- D.A NoSQL database system for document-based storage
Explanation
CORS controls which origins can access resources; misconfiguration can expose APIs.
Report an error in this question
Web SecurityMedium
Q18. What is a brute force attack?
- A.A CSS technique for overriding existing style rules
- B.Systematically trying all possible password combinations✓ Correct
- C.A physical attack on server hardware infrastructure
- D.A network protocol for secure data transmission
Explanation
Brute force attacks try every possible combination to crack passwords.
Report an error in this question
Web SecurityMedium
Q19. What is the purpose of the HttpOnly cookie flag?
- A.To encrypt the cookie data using symmetric encryption
- B.To prevent JavaScript from accessing the cookie✓ Correct
- C.To make cookies only work over HTTP connections
- D.To make the cookie persistent across browser sessions
Explanation
HttpOnly prevents client-side JavaScript from accessing the cookie.
Report an error in this question
Web SecurityMedium
Q20. What is OWASP?
- A.A web framework for building server applications
- B.A CSS standard for defining stylesheet specifications
- C.A relational database system for enterprise apps
- D.The Open Web Application Security Project guidelines✓ Correct
Explanation
OWASP publishes resources like the OWASP Top 10 listing critical security risks.
Report an error in this question
Web SecurityHard
Q21. What is a SQL injection attack and how is it prevented?
- A.A CSS vulnerability from untrusted stylesheet loading
- B.A database feature for optimizing query performance
- C.Inserting malicious SQL; prevented by parameterized queries✓ Correct
- D.A JavaScript error from uncaught promise rejections
Explanation
SQL injection is prevented by parameterized queries and prepared statements.
Report an error in this question
Web SecurityHard
Q22. What is the difference between symmetric and asymmetric encryption?
- A.They are identical in their encryption approach
- B.Asymmetric is always faster than symmetric encryption
- C.Symmetric uses one key; asymmetric uses a key pair✓ Correct
- D.Symmetric encryption requires two separate keys
Explanation
Symmetric uses one shared key, while asymmetric uses a public-private key pair.
Report an error in this question
Web SecurityHard
Q23. What is a man-in-the-middle (MITM) attack?
- A.A database corruption from concurrent write conflicts
- B.An attack intercepting communication between two parties✓ Correct
- C.A network administrator managing server infrastructure
- D.A CSS hack for overriding conflicting style declarations
Explanation
In MITM attacks, an attacker secretly intercepts communication between two parties.
Report an error in this question
Web SecurityHard
Q24. What is the SameSite cookie attribute?
- A.An attribute controlling cookies in cross-site requests✓ Correct
- B.A site name attribute used in HTML anchor tags
- C.A CSS property for styling site-specific page elements
- D.A database attribute for defining column data constraints
Explanation
SameSite restricts when cookies are sent cross-site: Strict, Lax, or None.
Report an error in this question
Web SecurityHard
Q25. What is a zero-day vulnerability?
- A.A CSS bug affecting zero-width element rendering
- B.A vulnerability lasting zero days before being fixed
- C.A database error caused by zero-division in queries
- D.A security flaw exploited before the vendor has a patch✓ Correct
Explanation
A zero-day vulnerability is unknown to the vendor and has no patch available.
Report an error in this question
Web SecurityHard
Q26. What is OAuth 2.0?
- A.An authorization framework for limited third-party access✓ Correct
- B.A JavaScript library for building authentication flows
- C.A CSS standard for defining cross-browser specifications
- D.A database protocol for encrypted data transmission
Explanation
OAuth 2.0 allows users to grant third-party apps limited access without sharing credentials.
Report an error in this question
Web SecurityHard
Q27. What is Subresource Integrity (SRI)?
- A.A database integrity check for verifying data consistency
- B.A CSS property for defining element integrity
- C.A feature verifying fetched resources are not tampered with✓ Correct
- D.A JavaScript framework for building secure web apps
Explanation
SRI uses cryptographic hashes to verify external resources haven't been altered.
Report an error in this question
Web SecurityHard
Q28. What is the purpose of rate limiting in security?
- A.Limiting the speed of CSS transition animations
- B.Restricting request frequency to prevent brute force✓ Correct
- C.Limiting the number of page loads per session
- D.Limiting the number of database queries per session
Explanation
Rate limiting controls request frequency to protect against attacks.
Report an error in this question
Web SecurityHard
Q29. What is X-Frame-Options used for?
- A.A CSS frame property for creating bordered layouts
- B.Preventing iframe embedding to stop clickjacking✓ Correct
- C.A JavaScript frame option for window management
- D.Framing images within decorative CSS borders
Explanation
X-Frame-Options prevents a page from being rendered in an iframe on another site.
Report an error in this question
Web SecurityHard
Q30. What is the difference between encryption at rest and in transit?
- A.At rest encryption is only for database systems
- B.At rest encrypts stored data; in transit encrypts transmitted✓ Correct
- C.They are identical in their security approach
- D.In transit encryption is only for local file systems
Explanation
At rest protects stored data, while in transit protects data moving between systems.
Report an error in this question