C

Web › Module 3 › Lesson 6

BeginnerModule 3Lesson 6/6

Quiz — Auth Flaws

10-question quiz on broken auth, sessions, JWTs, and IDOR

10 min+56 XP10 quiz
Module progress6 of 6

Opening

Authentication Flaws — Module Quiz

Ten questions covering login weaknesses, session hijacking, JWT pitfalls, IDOR, and your auth lab observations.

Knowledge Check

1

Credential stuffing uses:

Multiple choice

Knowledge Check

2

True or False: HttpOnly helps prevent JavaScript from reading session cookies.

True or False

Knowledge Check

3

Session fixation is mitigated by:

Multiple choice

Knowledge Check

4

The alg:none JWT flaw involves:

Multiple choice

Knowledge Check

5

IDOR is primarily a failure of:

Multiple choice

Knowledge Check

6

Select secure cookie practices:

Select all that apply

Knowledge Check

7

True or False: JWT payloads should be treated as confidential without encryption.

True or False

Knowledge Check

8

Weak HS256 secrets enable attackers to:

Multiple choice

Knowledge Check

9

Rate limiting on login helps against:

Multiple choice

Knowledge Check

10

Best lab ethics rule for auth testing?

Multiple choice

← Previous

Answer all 10 knowledge checks to continue. (0/10 answered)