Search Header Logo

Security Engineer Intern

Authored by Rizwaan Bashir

Information Technology (IT)

University

Used 1+ times

Security Engineer Intern
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

28 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

10 sec • 1 pt

What does setting `SameSite=Strict` on cookies help prevent?

XSS
CSRF
Clickjacking
CORS issues

2.

MULTIPLE CHOICE QUESTION

10 sec • 1 pt

Which header protects against Clickjacking attacks?

Content-Type
X-Content-Type-Options
X-Frame-Options
Cache-Control

3.

MULTIPLE CHOICE QUESTION

10 sec • 1 pt

In a broken access control test, what’s the best way to discover IDOR?

XSS injection
Changing URL parameters
Clearing cookies
Changing HTTP method

4.

MULTIPLE CHOICE QUESTION

10 sec • 1 pt

In OAuth, what is the purpose of the `state` parameter?

Session tracking
Scope restriction
CSRF protection
Token refresh

5.

MULTIPLE CHOICE QUESTION

10 sec • 1 pt

You bypass a login by modifying a JWT’s algorithm to `none`. What’s this flaw?

Key reuse
Signature validation bypass
Replay attack
Session fixation

6.

MULTIPLE CHOICE QUESTION

10 sec • 1 pt

What does SSRF in a cloud app often lead to?

XSS
IAM access
File upload
Shellshock

7.

MULTIPLE CHOICE QUESTION

10 sec • 1 pt

Which AWS service metadata IP is often targeted by SSRF?

127.0.0.1
0.0.0.0
169.254.169.254
192.168.1.1

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Microsoft

Continue with Microsoft

or continue with

Facebook

Facebook

Apple

Apple

Others

Others

Already have an account?