Skip to contentExploitQuest

Web Application Security

Web Application Security Exam

16 questions60s each · ~16 minpass 70%merit 80% · distinction 90%

One question at a time, each on a server-timed clock. You cannot go back, and a late answer is marked wrong — so read quickly and commit. Pass and you earn a verifiable credential.

What it tests

  • Recognise input crossing from data into code, and write the parameterised query that leaves no border to cross
  • Identify a missing object-level authorisation, and explain why a guessable id or a hidden link is not access control
  • Trace untrusted input into a file path, and constrain it to a directory it cannot climb out of
  • Read what a session token asks to be trusted on, and require the verifier to pin the algorithm and re-read authority server-side
  • Distinguish stored from reflected cross-site scripting, and encode a value for the exact context it is rendered into
  • Judge the common non-fixes — hand-escaping, keyword and tag blocklists, a web application firewall — for what they actually buy
  • State the authorisation boundary that separates learning these techniques from committing an offence
  • Name the one pattern beneath all five: input allowed to make a decision the program should have made itself

Sign in to sit the exam — a credential is issued to your account.

Exam — Web Application Security Exam · ExploitQuest