Web security
Silver exam
Twenty-four questions across the whole course at working depth: read real code, spot the usual holes, choose the right fix and run the everyday commands. Think about what happens when each value is hostile.
- 16 questions
- 20 minutes
- Pass mark 80%
- At least 6 hands-on tasks
Covers SQL injectionCross-site scriptingPasswordsSessions, cookies and CSRFAccess controlSecrets and HTTPSSupply chainLogging and alertingThreat modeling
The clock cannot be paused, and leaving counts as an attempt.