18 Superglobals & Web questions from the PHP bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.
Free to start: the 2-minute IT readiness check — six questions and a result.
A.an injection flaw where unescaped attacker input is rendered as active markup in a victim's browser, mitigated by output encoding with htmlspecialchars
B.the object-oriented database abstraction layer offering one consistent API with prepared statements across many drivers like MySQL and PostgreSQL
C.a server-side mechanism that persists user data across multiple requests by linking them through an identifier carried in a cookie
D.a built-in associative array such as the GET or POST array that is automatically available in every scope without an import or global declaration
Answer + AI explanation with Pro
2. Which term means: "a built-in associative array such as the GET or POST array that is automatically available in every scope without an import or global declaration"?
Junior
A.Session
B.PDO
C.Cross-site scripting
D.Superglobal
Answer + AI explanation with Pro
3. Which statement is correct?
Junior
A.Superglobal — the object-oriented database abstraction layer offering one consistent API with prepared statements across many drivers like MySQL and PostgreSQL
B.Superglobal — an injection flaw where unescaped attacker input is rendered as active markup in a victim's browser, mitigated by output encoding with htmlspecialchars
C.Superglobal — a server-side mechanism that persists user data across multiple requests by linking them through an identifier carried in a cookie
D.Superglobal — a built-in associative array such as the GET or POST array that is automatically available in every scope without an import or global declaration
Answer + AI explanation with Pro
4. What is Session?
Junior
A.the function that creates a secure salted one-way digest of a plaintext credential using a strong adaptive algorithm such as bcrypt by default
B.the object-oriented database abstraction layer offering one consistent API with prepared statements across many drivers like MySQL and PostgreSQL
C.an injection flaw where unescaped attacker input is rendered as active markup in a victim's browser, mitigated by output encoding with htmlspecialchars
D.a server-side mechanism that persists user data across multiple requests by linking them through an identifier carried in a cookie
Answer + AI explanation with Pro
5. Which term means: "a server-side mechanism that persists user data across multiple requests by linking them through an identifier carried in a cookie"?
Junior
A.Session
B.PDO
C.Superglobal
D.Cross-site scripting
Answer + AI explanation with Pro
6. Which statement is correct?
Junior
A.Session — an injection flaw where unescaped attacker input is rendered as active markup in a victim's browser, mitigated by output encoding with htmlspecialchars
B.Session — a precompiled SQL template whose user values are sent separately as bound parameters, neutralising injection by keeping data out of the query structure
C.Session — a server-side mechanism that persists user data across multiple requests by linking them through an identifier carried in a cookie
D.Session — a built-in associative array such as the GET or POST array that is automatically available in every scope without an import or global declaration
Answer + AI explanation with Pro
7. What is Prepared statement?
Mid
A.an injection flaw where unescaped attacker input is rendered as active markup in a victim's browser, mitigated by output encoding with htmlspecialchars
B.a server-side mechanism that persists user data across multiple requests by linking them through an identifier carried in a cookie
C.the object-oriented database abstraction layer offering one consistent API with prepared statements across many drivers like MySQL and PostgreSQL
D.a precompiled SQL template whose user values are sent separately as bound parameters, neutralising injection by keeping data out of the query structure
Answer + AI explanation with Pro
8. Which term means: "a precompiled SQL template whose user values are sent separately as bound parameters, neutralising injection by keeping data out of the query structure"?
Mid
A.PDO
B.Session
C.Superglobal
D.Prepared statement
Answer + AI explanation with Pro
9. Which statement is correct?
Mid
A.Prepared statement — a server-side mechanism that persists user data across multiple requests by linking them through an identifier carried in a cookie
B.Prepared statement — a precompiled SQL template whose user values are sent separately as bound parameters, neutralising injection by keeping data out of the query structure
C.Prepared statement — an injection flaw where unescaped attacker input is rendered as active markup in a victim's browser, mitigated by output encoding with htmlspecialchars
D.Prepared statement — a built-in associative array such as the GET or POST array that is automatically available in every scope without an import or global declaration
Answer + AI explanation with Pro
10. What is PDO?
Mid
A.a server-side mechanism that persists user data across multiple requests by linking them through an identifier carried in a cookie
B.an injection flaw where unescaped attacker input is rendered as active markup in a victim's browser, mitigated by output encoding with htmlspecialchars
C.the function that creates a secure salted one-way digest of a plaintext credential using a strong adaptive algorithm such as bcrypt by default
D.the object-oriented database abstraction layer offering one consistent API with prepared statements across many drivers like MySQL and PostgreSQL
Answer + AI explanation with Pro
11. Which term means: "the object-oriented database abstraction layer offering one consistent API with prepared statements across many drivers like MySQL and PostgreSQL"?
Mid
A.Cross-site scripting
B.PDO
C.Session
D.Superglobal
Answer + AI explanation with Pro
12. Which statement is correct?
Mid
A.PDO — an injection flaw where unescaped attacker input is rendered as active markup in a victim's browser, mitigated by output encoding with htmlspecialchars
B.PDO — a precompiled SQL template whose user values are sent separately as bound parameters, neutralising injection by keeping data out of the query structure
C.PDO — the object-oriented database abstraction layer offering one consistent API with prepared statements across many drivers like MySQL and PostgreSQL
D.PDO — a server-side mechanism that persists user data across multiple requests by linking them through an identifier carried in a cookie
Answer + AI explanation with Pro
13. What is password_hash?
Mid
A.the object-oriented database abstraction layer offering one consistent API with prepared statements across many drivers like MySQL and PostgreSQL
B.the function that creates a secure salted one-way digest of a plaintext credential using a strong adaptive algorithm such as bcrypt by default
C.an injection flaw where unescaped attacker input is rendered as active markup in a victim's browser, mitigated by output encoding with htmlspecialchars
D.a precompiled SQL template whose user values are sent separately as bound parameters, neutralising injection by keeping data out of the query structure
Answer + AI explanation with Pro
14. Which term means: "the function that creates a secure salted one-way digest of a plaintext credential using a strong adaptive algorithm such as bcrypt by default"?
Mid
A.Prepared statement
B.PDO
C.Superglobal
D.password_hash
Answer + AI explanation with Pro
15. Which statement is correct?
Mid
A.password_hash — the function that creates a secure salted one-way digest of a plaintext credential using a strong adaptive algorithm such as bcrypt by default
B.password_hash — a built-in associative array such as the GET or POST array that is automatically available in every scope without an import or global declaration
C.password_hash — the object-oriented database abstraction layer offering one consistent API with prepared statements across many drivers like MySQL and PostgreSQL
D.password_hash — a precompiled SQL template whose user values are sent separately as bound parameters, neutralising injection by keeping data out of the query structure
Answer + AI explanation with Pro
16. What is Cross-site scripting?
Senior
A.an injection flaw where unescaped attacker input is rendered as active markup in a victim's browser, mitigated by output encoding with htmlspecialchars
B.a built-in associative array such as the GET or POST array that is automatically available in every scope without an import or global declaration
C.the function that creates a secure salted one-way digest of a plaintext credential using a strong adaptive algorithm such as bcrypt by default
D.a precompiled SQL template whose user values are sent separately as bound parameters, neutralising injection by keeping data out of the query structure
Answer + AI explanation with Pro
17. Which term means: "an injection flaw where unescaped attacker input is rendered as active markup in a victim's browser, mitigated by output encoding with htmlspecialchars"?
Senior
A.Cross-site scripting
B.Session
C.Superglobal
D.Prepared statement
Answer + AI explanation with Pro
18. Which statement is correct?
Senior
A.Cross-site scripting — an injection flaw where unescaped attacker input is rendered as active markup in a victim's browser, mitigated by output encoding with htmlspecialchars
B.Cross-site scripting — a precompiled SQL template whose user values are sent separately as bound parameters, neutralising injection by keeping data out of the query structure
C.Cross-site scripting — a built-in associative array such as the GET or POST array that is automatically available in every scope without an import or global declaration
D.Cross-site scripting — the object-oriented database abstraction layer offering one consistent API with prepared statements across many drivers like MySQL and PostgreSQL
Answer + AI explanation with Pro
Free to start
Start with a free readiness check
Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Superglobals & Web question come with Pro.