HomeSubjectsUniversityBlogAbout

Web Security

Topic in Web Development

210 total MCQsShowing 30 with explanations10 Easy10 Medium10 Hard

About This Topic

Web security is the practice of protecting websites, web applications and their users from attacks that steal data, hijack sessions or run malicious code. The OWASP Top 10 frames most questions. You must distinguish stored, reflected and DOM-based cross-site scripting (XSS), explain cross-site request forgery (CSRF) and its defences like anti-CSRF tokens and SameSite cookies, and show how parameterised queries stop SQL injection. Know HTTPS and TLS certificates, password hashing with bcrypt, multi-factor authentication, OAuth 2.0 flows, and cookie flags (Secure, HttpOnly, SameSite). Security headers are frequently tested, including Content Security Policy with nonces, HSTS, X-Frame-Options against clickjacking, and CORS.

Below are 30 practice questions from a pool of 210 Web Security MCQs, one of 17 topics in Web Development. Each shows the correct answer with an explanation; when you are ready, take a timed quiz to test recall under exam conditions.

Practice Questions

Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.

Web SecurityEasy

Q1. What is HTTPS?

  1. A.HTTP with encryption using TLS/SSL for security✓ Correct
  2. B.A database protocol for encrypted connections
  3. C.A faster version of HTTP for static content
  4. D.A programming language for server applications

Explanation

HTTPS encrypts data between browser and server using TLS/SSL.

Report an error in this question

Web SecurityEasy

Q2. What is a password hash?

  1. A.A one-way transformation into a fixed-length string✓ Correct
  2. B.A password hint for helping users remember
  3. C.A password reset link sent via email notification
  4. D.An encrypted password stored with a cipher key

Explanation

Hashing converts passwords into irreversible fixed-length strings.

Report an error in this question

Web SecurityEasy

Q3. What is XSS (Cross-Site Scripting)?

  1. A.A JavaScript framework for building secure apps
  2. B.A CSS extension for adding custom properties
  3. C.A vulnerability where malicious scripts are injected✓ Correct
  4. D.A database attack targeting stored procedures

Explanation

XSS attacks inject malicious scripts into web pages viewed by other users.

Report an error in this question

Web SecurityEasy

Q4. What is a firewall?

  1. A.A NoSQL database for storing security records
  2. B.A JavaScript library for client-side validation
  3. C.A CSS border property for styling elements
  4. D.A system monitoring and controlling network traffic✓ Correct

Explanation

A firewall filters network traffic based on security rules.

Report an error in this question

Web SecurityEasy

Q5. What is authentication?

  1. A.A JavaScript function for data validation
  2. B.The process of verifying a user's identity✓ Correct
  3. C.A CSS technique for styling form elements
  4. D.Authorizing access to protected resources

Explanation

Authentication verifies who a user is.

Report an error in this question

Web SecurityEasy

Q6. What is a cookie in web security?

  1. A.A CSS property for styling decorated elements
  2. B.A small data piece stored for session management✓ Correct
  3. C.A browser game for entertainment purposes
  4. D.A JavaScript variable stored in local memory

Explanation

Cookies are small data files stored by the browser.

Report an error in this question

Web SecurityEasy

Q7. What does SSL stand for?

  1. A.Secure Socket Layer✓ Correct
  2. B.Simple Security Layer
  3. C.Secure Server Link
  4. D.Server Side Logic

Explanation

SSL stands for Secure Sockets Layer.

Report an error in this question

Web SecurityEasy

Q8. What is a CAPTCHA?

  1. A.A test distinguishing humans from automated bots✓ Correct
  2. B.A type of database for storing user accounts
  3. C.A JavaScript function for validating form data
  4. D.A CSS framework for building secure page layouts

Explanation

CAPTCHA verifies that a user is human and not an automated bot.

Report an error in this question

Web SecurityEasy

Q9. What is two-factor authentication (2FA)?

  1. A.Using two passwords for login authentication
  2. B.Using two browsers for testing compatibility
  3. C.Having two accounts for backup and recovery
  4. D.A method requiring two forms of identification✓ Correct

Explanation

2FA requires two different verification methods for additional security.

Report an error in this question

Web SecurityEasy

Q10. Why should user input be validated?

  1. A.To improve SEO ranking in search engine results
  2. B.To improve CSS styling across different browsers
  3. C.To speed up the database query execution time
  4. D.To prevent malicious data and protect against attacks✓ Correct

Explanation

Input validation ensures user-supplied data is safe and properly formatted.

Report an error in this question

Web SecurityMedium

Q11. What is CSRF (Cross-Site Request Forgery)?

  1. A.An attack tricking users into actions on authenticated sites✓ Correct
  2. B.A CSS framework for building styled web components
  3. C.A JavaScript error caused by invalid syntax in code
  4. D.A database attack targeting table join vulnerabilities

Explanation

CSRF exploits an authenticated session to make unauthorized requests.

Report an error in this question

Web SecurityMedium

Q12. How is CSRF typically prevented?

  1. A.Disabling JavaScript execution in the browser
  2. B.Using anti-CSRF tokens to verify request origin✓ Correct
  3. C.Using CSS styles to hide form submission buttons
  4. D.Using longer and more complex user passwords

Explanation

Anti-CSRF tokens verify that requests originate from the legitimate site.

Report an error in this question

Web SecurityMedium

Q13. What is Content Security Policy (CSP)?

  1. A.A database policy for query execution permissions
  2. B.A JavaScript policy for variable access control
  3. C.A CSS policy for restricting style inheritance
  4. D.An HTTP header restricting which resources load✓ Correct

Explanation

CSP restricts which resources a page can load, mitigating XSS attacks.

Report an error in this question

Web SecurityMedium

Q14. What is JWT (JSON Web Token)?

  1. A.A database token for authenticating query access
  2. B.A compact self-contained token for secure data transfer✓ Correct
  3. C.A CSS token for custom property values
  4. D.A JavaScript variable for storing session data

Explanation

JWT is a signed token containing claims used for stateless authentication.

Report an error in this question

Web SecurityMedium

Q15. What is the principle of least privilege?

  1. A.Disabling all non-essential application features
  2. B.Giving admin access to every application user
  3. C.Granting users only the minimum needed permissions✓ Correct
  4. D.Using the simplest possible password for accounts

Explanation

Least privilege limits permissions to the bare minimum required.

Report an error in this question

Web SecurityMedium

Q16. What is input sanitization?

  1. A.Compressing HTML to reduce the total page size
  2. B.Formatting JSON data for consistent key ordering
  3. C.Removing or encoding dangerous characters from input✓ Correct
  4. D.Cleaning CSS code by removing unused selectors

Explanation

Sanitization cleans user input by removing or encoding special characters.

Report an error in this question

Web SecurityMedium

Q17. What is CORS and why is it a security concern?

  1. A.A JavaScript library for making HTTP request calls
  2. B.Cross-Origin Resource Sharing; misconfiguration exposes data✓ Correct
  3. C.A CSS framework for cross-browser styling consistency
  4. D.A NoSQL database system for document-based storage

Explanation

CORS controls which origins can access resources; misconfiguration can expose APIs.

Report an error in this question

Web SecurityMedium

Q18. What is a brute force attack?

  1. A.A CSS technique for overriding existing style rules
  2. B.Systematically trying all possible password combinations✓ Correct
  3. C.A physical attack on server hardware infrastructure
  4. D.A network protocol for secure data transmission

Explanation

Brute force attacks try every possible combination to crack passwords.

Report an error in this question

Web SecurityMedium

Q19. What is the purpose of the HttpOnly cookie flag?

  1. A.To encrypt the cookie data using symmetric encryption
  2. B.To prevent JavaScript from accessing the cookie✓ Correct
  3. C.To make cookies only work over HTTP connections
  4. D.To make the cookie persistent across browser sessions

Explanation

HttpOnly prevents client-side JavaScript from accessing the cookie.

Report an error in this question

Web SecurityMedium

Q20. What is OWASP?

  1. A.A web framework for building server applications
  2. B.A CSS standard for defining stylesheet specifications
  3. C.A relational database system for enterprise apps
  4. D.The Open Web Application Security Project guidelines✓ Correct

Explanation

OWASP publishes resources like the OWASP Top 10 listing critical security risks.

Report an error in this question

Web SecurityHard

Q21. What is a SQL injection attack and how is it prevented?

  1. A.A CSS vulnerability from untrusted stylesheet loading
  2. B.A database feature for optimizing query performance
  3. C.Inserting malicious SQL; prevented by parameterized queries✓ Correct
  4. D.A JavaScript error from uncaught promise rejections

Explanation

SQL injection is prevented by parameterized queries and prepared statements.

Report an error in this question

Web SecurityHard

Q22. What is the difference between symmetric and asymmetric encryption?

  1. A.They are identical in their encryption approach
  2. B.Asymmetric is always faster than symmetric encryption
  3. C.Symmetric uses one key; asymmetric uses a key pair✓ Correct
  4. D.Symmetric encryption requires two separate keys

Explanation

Symmetric uses one shared key, while asymmetric uses a public-private key pair.

Report an error in this question

Web SecurityHard

Q23. What is a man-in-the-middle (MITM) attack?

  1. A.A database corruption from concurrent write conflicts
  2. B.An attack intercepting communication between two parties✓ Correct
  3. C.A network administrator managing server infrastructure
  4. D.A CSS hack for overriding conflicting style declarations

Explanation

In MITM attacks, an attacker secretly intercepts communication between two parties.

Report an error in this question

Web SecurityHard

Q24. What is the SameSite cookie attribute?

  1. A.An attribute controlling cookies in cross-site requests✓ Correct
  2. B.A site name attribute used in HTML anchor tags
  3. C.A CSS property for styling site-specific page elements
  4. D.A database attribute for defining column data constraints

Explanation

SameSite restricts when cookies are sent cross-site: Strict, Lax, or None.

Report an error in this question

Web SecurityHard

Q25. What is a zero-day vulnerability?

  1. A.A CSS bug affecting zero-width element rendering
  2. B.A vulnerability lasting zero days before being fixed
  3. C.A database error caused by zero-division in queries
  4. D.A security flaw exploited before the vendor has a patch✓ Correct

Explanation

A zero-day vulnerability is unknown to the vendor and has no patch available.

Report an error in this question

Web SecurityHard

Q26. What is OAuth 2.0?

  1. A.An authorization framework for limited third-party access✓ Correct
  2. B.A JavaScript library for building authentication flows
  3. C.A CSS standard for defining cross-browser specifications
  4. D.A database protocol for encrypted data transmission

Explanation

OAuth 2.0 allows users to grant third-party apps limited access without sharing credentials.

Report an error in this question

Web SecurityHard

Q27. What is Subresource Integrity (SRI)?

  1. A.A database integrity check for verifying data consistency
  2. B.A CSS property for defining element integrity
  3. C.A feature verifying fetched resources are not tampered with✓ Correct
  4. D.A JavaScript framework for building secure web apps

Explanation

SRI uses cryptographic hashes to verify external resources haven't been altered.

Report an error in this question

Web SecurityHard

Q28. What is the purpose of rate limiting in security?

  1. A.Limiting the speed of CSS transition animations
  2. B.Restricting request frequency to prevent brute force✓ Correct
  3. C.Limiting the number of page loads per session
  4. D.Limiting the number of database queries per session

Explanation

Rate limiting controls request frequency to protect against attacks.

Report an error in this question

Web SecurityHard

Q29. What is X-Frame-Options used for?

  1. A.A CSS frame property for creating bordered layouts
  2. B.Preventing iframe embedding to stop clickjacking✓ Correct
  3. C.A JavaScript frame option for window management
  4. D.Framing images within decorative CSS borders

Explanation

X-Frame-Options prevents a page from being rendered in an iframe on another site.

Report an error in this question

Web SecurityHard

Q30. What is the difference between encryption at rest and in transit?

  1. A.At rest encryption is only for database systems
  2. B.At rest encrypts stored data; in transit encrypts transmitted✓ Correct
  3. C.They are identical in their security approach
  4. D.In transit encryption is only for local file systems

Explanation

At rest protects stored data, while in transit protects data moving between systems.

Report an error in this question

Ready to test yourself on Web Security?

Take a timed quiz drawn from 210+ questions on this topic. No signup required — your progress saves in your browser.

Start Web Security Quiz