Home > Know IT All Trivia: Application security
Quiz:
EMAIL THIS

Know IT All Trivia: Application security

25 Apr 2006 | SearchAppSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



Test your knowledge of application security with these trivia questions. Scroll down to the bottom of the page for the correct answer.

1.) A cracker exploits this in order to use a Web application to transport an attack to a user's browser. It can expose a local machine or enable an attacker to spoof content.
a. unvalidated parameter
b. buffer overflow
c. command injection flaw
d. cross-site scripting flaw

2.) This language is a new security interoperability standard within the Organization for the Advancement of Structured Information Standards (OASIS) designed to provide a standard way for application vulnerabilities to be defined and classified.
a. XrML
b. AVDL
c. SAML
d. XACML

3.) This attack against Web applications involves getting information from a server by modifying the session's cookie.
a. chaffing
b. brain fingerprinting
c. cookie poisoning
d. cookie hijacking

4.) In this type of attack against database-driven applications, the intruder manipulates a site's Web-based interfaces to force the database to execute undesirable code.
a. smurfing
b. SQL injection
c. nuking
d. phreaking

5.) This protects Web applications written in Perl from dangerous code by assuming that all user input is potentially malicious and placing restrictions on the actions that the script may perform on that input.
a. promiscuous mode
b. Tempest-shielding
c. data key
d. taint mode





What do you think of our trivia questions? Are they too easy? Too hard? Let us know.










Want to learn more about securing your applications? Check out this learning guide Top 10 most critical Web application security vulnerabilities.










ANSWERS:

1.) d. cross-site scripting flaw
Learn more about common vulnerabilities in the Vulnerabilities section of SearchAppSecurity.com.

2.) b. AVDL
Learn more about Web security standards in the Standards section of SearchAppSecurity.com

3.) c. cookie poisoning
For more information about cookie poisoning, read the definition in SearchAppSecurity.com's glossary.

4.) b. SQL injection
Learn more about SQL injection in the tip "SQL injection: Developers fight back"

5.) d. taint mode
For more information on vulnerabilities due to poorly constructed code, read the tip Buffer-overflow attacks: How do they work?.



Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Building security into the SDLC (Software development life cycle)
Problems caused by skipping analysis stage of SDLC
Inexpensive phase of SDLC to catch and fix bugs
GatherSpace beefs up cloud-based requirements management
ALM: Best of breed vs. complete systems
Software development life cycle phases, iterations, explained step by step
The role of quality assurance (QA) pros in software security
Common software security risks and oversights
Why the quality assurance department should be involved in testing
How to develop secure applications
Secure software development practices 'not rocket science'

Software security testing and techniques
Free Web proxy security tools software testers should get to know
How to get management on board with Web 2.0 security issues
Web application security best practices: Tips on implementation
Testing strategies for complex environments
How to make your software tamperproof
Ways to approach application performance testing on a tight budget
How can I tell if my software security has been breached?
Is online application testing for smartphones different from other software testing?
Software testers facing six big challenges today, StarWest keynoter says
Lesser-known free software testing tools testers should try

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Software Quality Testing - Research and White Papers
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts