01. Skimming responses from a student housing portal, a tester groups the error codes into the 4xx and 5xx families. What distinguishes a 4xx status from a 5xx status?
a) A 4xx means the request was redirected to another location, while a 5xx means the request completed successfully
b) A 4xx reports a problem with the client's request, while a 5xx reports a failure on the server
c) Both families mean the request succeeded
d) A 4xx is always a security finding and a 5xx never is
02. You are an in-house AppSec engineer at a regional bank. After you reported an injectable query, the developers moved the same logic into a stored procedure that assembles the SQL by concatenating the incoming parameter into a string it then executes, and they now report the flaw fixed.
How should you assess their claim that the vulnerability is resolved?
a) The flaw is fixed, because moving the logic into the database removes the application's query string
b) The flaw is fixed, because a stored procedure runs with the database's own privileges, type-checks and quotes each argument and cannot be injected
c) The flaw remains, but only if the procedure is called over an unencrypted connection
d) The flaw remains, because a stored procedure that assembles and executes a query string from concatenated input treats that input as code just as the original query did, and only binding the value as a parameter fixes it
03. After a developer parameterized the login query you reported on a university LMS, you retest and find injection still works through a separate search-filter parameter on the same application.
What does this most likely indicate about the remediation?
a) The search parameter is only a false positive
b) The fix covered the reported query but missed other dynamic queries
c) The originally reported login query was itself parameterized incorrectly and remains injectable
d) Parameterized queries are fundamentally unable to protect any search or filter parameter
04. Testing a veterinary clinic booking site, a tester compares two request headers on a state-changing POST: Origin and Referer. How does the Origin header differ from the Referer header here?
a) Referer is sent only on cross-site requests, while Origin appears on every same-site navigation the user makes
b) Referer can never be used at all to check the source of a request
c) Origin is set by the server, cached, and echoed back
d) Origin names only the scheme, host and port, without the path
05. On an authorized test of a logistics tracking API, you have a stable injection point that already returns query results in the page. A stakeholder asks whether you could read an application configuration file from the server through the same flaw.
What primarily determines whether the injection can read a file from the server's filesystem?
a) Whether the injected value falls inside a numeric context or inside a quoted string literal within the query
b) Whether the application displays a verbose database error
c) Whether the database account holds the privileges and file-access features the operation needs
d) The number of columns the original query returns to the page
06. A confirmed SQL injection in an insurance quote tool cannot be re-coded before the next release. You are asked to recommend stopgaps that limit what a successful injection could achieve in the meantime.
Which two stopgaps most reduce the potential impact while the code fix is pending?
(Choose two.)
a) Increase the application's session timeout window
b) Restrict the database account to the least privilege the application requires
c) Enable client-side validation of the input in the browser so malformed values are rejected before the form is submitted
d) Return generic error pages so database messages are not disclosed
07. Checking one in-scope address for a hotel chain, a tester sends requests to 192.0.2.40. With no recognized host name it returns a default page, with Host: book.example.com it returns the booking site, and with Host: loyalty.example.com it returns a points portal.
What explains the different responses from one address?
a) The server ignored the Host header and the browser cache supplied the pages
b) The server uses name-based virtual hosting and picks which site to serve from the Host header it receives
c) A load balancer picks a back end at random, and the pages differ only by chance
d) DNS resolved each host name to a different address
08. Under a bug-bounty program's rules you have a matched-column UNION against a retailer's search results, but your injected marker appears in only one of several columns. You want to place extracted data where it will actually show.
How do you determine which column position is rendered?
a) Raise the ORDER BY index step by step until an error reveals the displayed column position
b) Add placeholder values until the query stops raising an error, then assume the first column is the one displayed
c) Put a distinct marker in each column and see which appears
d) Inspect the response headers to learn which column the application maps to its output field
09. You have manually confirmed a time-based blind injection, in scope, on a SaaS HR application, and you now need to extract a large number of fields. You are weighing continued manual extraction against running sqlmap.
What is the strongest justification for using sqlmap at this point?
a) It automates the many timed requests that blind extraction requires
b) It proves the finding is valid, so no further confirmation is ever needed
c) It lets the tester work outside the authorized scope
d) It uncovers application workflow and business-logic flaws that a manual test overlooked
10. Testing a dental practice portal, a tester compares two form submissions in proxy history. The profile form's body reads name=Ana+Silva&city=Porto, while the X-ray upload request carries Content-Type: multipart/form-data; boundary=----b7Qx and a body split into delimited parts.
What explains the difference between the two request bodies?
a) The boundary is a session token the server checks, and multipart is chosen to protect the upload
b) Multipart carries files as separate parts; URL encoding cannot
c) The URL-encoded profile form is encrypted, while the multipart upload body travels in clear text
d) Multipart is used only with GET, and URL encoding only with POST, so the two forms used different methods