AppSec · OWASP Top 10 interview questions

63 AppSec · OWASP Top 10 questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What is Injection?

Junior
  1. A.injecting SQL via unsanitized input to alter the meaning of a database query
  2. B.XSS where the malicious script is persisted server-side and served to every visitor
  3. C.weak, missing, or misused cryptography that exposes sensitive data (renamed from Sensitive Data Exposure)
  4. D.flaw where untrusted input is interpreted as part of a command or query (e.g. SQL, OS, LDAP)

Answer + AI explanation with Pro

2. Which term means: "flaw where untrusted input is interpreted as part of a command or query (e.g. SQL, OS, LDAP)"?

Junior
  1. A.Blind SQL injection
  2. B.Software and Data Integrity Failures
  3. C.Injection
  4. D.Server-Side Request Forgery (SSRF)

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.Injection — flaw where untrusted input is interpreted as part of a command or query (e.g. SQL, OS, LDAP)
  2. B.Injection — tricking the server into making requests to attacker-chosen internal or external URLs; added to Top 10 in 2021
  3. C.Injection — insecure default settings, verbose errors, or unpatched features that expose the application
  4. D.Injection — injecting properties into JavaScript Object.prototype to alter app behavior or escalate to RCE

Answer + AI explanation with Pro

4. What is SQL Injection?

Junior
  1. A.failure to enforce restrictions so users can act outside their intended permissions; #1 in OWASP Top 10 2021
  2. B.injecting SQL via unsanitized input to alter the meaning of a database query
  3. C.flaw where untrusted input is interpreted as part of a command or query (e.g. SQL, OS, LDAP)
  4. D.insufficient logging, detection, or alerting that delays breach discovery and response

Answer + AI explanation with Pro

5. Which term means: "injecting SQL via unsanitized input to alter the meaning of a database query"?

Junior
  1. A.Cryptographic Failures
  2. B.SQL Injection
  3. C.Cross-Site Scripting (XSS)
  4. D.DOM-based XSS

Answer + AI explanation with Pro

6. Which statement is correct?

Junior
  1. A.SQL Injection — injecting SQL via unsanitized input to alter the meaning of a database query
  2. B.SQL Injection — XSS where the malicious script is persisted server-side and served to every visitor
  3. C.SQL Injection — weaknesses like credential stuffing, weak passwords, or broken session management
  4. D.SQL Injection — binding client-supplied input to object fields the user should not control (e.g. setting isAdmin=true)

Answer + AI explanation with Pro

7. What is Cross-Site Scripting (XSS)?

Junior
  1. A.weak, missing, or misused cryptography that exposes sensitive data (renamed from Sensitive Data Exposure)
  2. B.injecting properties into JavaScript Object.prototype to alter app behavior or escalate to RCE
  3. C.weaknesses like credential stuffing, weak passwords, or broken session management
  4. D.injecting attacker-controlled script that executes in another user's browser session

Answer + AI explanation with Pro

8. Which term means: "injecting attacker-controlled script that executes in another user's browser session"?

Junior
  1. A.Vulnerable and Outdated Components
  2. B.Cross-Site Scripting (XSS)
  3. C.Injection
  4. D.Identification and Authentication Failures

Answer + AI explanation with Pro

9. Which statement is correct?

Junior
  1. A.Cross-Site Scripting (XSS) — using libraries or frameworks with known vulnerabilities or that are unsupported/unpatched
  2. B.Cross-Site Scripting (XSS) — injecting attacker-controlled script that executes in another user's browser session
  3. C.Cross-Site Scripting (XSS) — exposing an internal object key (e.g. /account?id=123) without authorization checks, a form of broken access control
  4. D.Cross-Site Scripting (XSS) — insufficient logging, detection, or alerting that delays breach discovery and response

Answer + AI explanation with Pro

10. What is Broken Access Control?

Junior
  1. A.insufficient logging, detection, or alerting that delays breach discovery and response
  2. B.injecting SQL via unsanitized input to alter the meaning of a database query
  3. C.flaw where untrusted input is interpreted as part of a command or query (e.g. SQL, OS, LDAP)
  4. D.failure to enforce restrictions so users can act outside their intended permissions; #1 in OWASP Top 10 2021

Answer + AI explanation with Pro

11. Which term means: "failure to enforce restrictions so users can act outside their intended permissions; #1 in OWASP Top 10 2021"?

Junior
  1. A.Command injection
  2. B.Blind SQL injection
  3. C.Open redirect
  4. D.Broken Access Control

Answer + AI explanation with Pro

12. Which statement is correct?

Junior
  1. A.Broken Access Control — weaknesses like credential stuffing, weak passwords, or broken session management
  2. B.Broken Access Control — failure to enforce restrictions so users can act outside their intended permissions; #1 in OWASP Top 10 2021
  3. C.Broken Access Control — SQL injection inferred from boolean or timing behavior when no direct output is returned
  4. D.Broken Access Control — injecting OS commands through unsanitized input passed to a system shell

Answer + AI explanation with Pro

13. What is Security Misconfiguration?

Junior
  1. A.XSS where the malicious script is persisted server-side and served to every visitor
  2. B.injecting SQL via unsanitized input to alter the meaning of a database query
  3. C.insecure default settings, verbose errors, or unpatched features that expose the application
  4. D.failure to enforce restrictions so users can act outside their intended permissions; #1 in OWASP Top 10 2021

Answer + AI explanation with Pro

14. Which term means: "insecure default settings, verbose errors, or unpatched features that expose the application"?

Junior
  1. A.Server-Side Request Forgery (SSRF)
  2. B.DOM-based XSS
  3. C.Security Misconfiguration
  4. D.Identification and Authentication Failures

Answer + AI explanation with Pro

15. Which statement is correct?

Junior
  1. A.Security Misconfiguration — using libraries or frameworks with known vulnerabilities or that are unsupported/unpatched
  2. B.Security Misconfiguration — unvalidated redirect parameter that sends users to an attacker-chosen external site
  3. C.Security Misconfiguration — injecting properties into JavaScript Object.prototype to alter app behavior or escalate to RCE
  4. D.Security Misconfiguration — insecure default settings, verbose errors, or unpatched features that expose the application

Answer + AI explanation with Pro

16. What is Cryptographic Failures?

Junior
  1. A.XSS executed entirely client-side when JavaScript writes untrusted data into the DOM
  2. B.weak, missing, or misused cryptography that exposes sensitive data (renamed from Sensitive Data Exposure)
  3. C.abusing an XML parser that resolves external entities to read files or reach internal systems
  4. D.binding client-supplied input to object fields the user should not control (e.g. setting isAdmin=true)

Answer + AI explanation with Pro

17. Which term means: "weak, missing, or misused cryptography that exposes sensitive data (renamed from Sensitive Data Exposure)"?

Junior
  1. A.Blind SQL injection
  2. B.Cryptographic Failures
  3. C.Security Logging and Monitoring Failures
  4. D.SQL Injection

Answer + AI explanation with Pro

18. Which statement is correct?

Junior
  1. A.Cryptographic Failures — exposing an internal object key (e.g. /account?id=123) without authorization checks, a form of broken access control
  2. B.Cryptographic Failures — injecting attacker-controlled script that executes in another user's browser session
  3. C.Cryptographic Failures — weak, missing, or misused cryptography that exposes sensitive data (renamed from Sensitive Data Exposure)
  4. D.Cryptographic Failures — injecting OS commands through unsanitized input passed to a system shell

Answer + AI explanation with Pro

19. What is Insecure Direct Object Reference (IDOR)?

Mid
  1. A.weak, missing, or misused cryptography that exposes sensitive data (renamed from Sensitive Data Exposure)
  2. B.injecting properties into JavaScript Object.prototype to alter app behavior or escalate to RCE
  3. C.exposing an internal object key (e.g. /account?id=123) without authorization checks, a form of broken access control
  4. D.weaknesses like credential stuffing, weak passwords, or broken session management

Answer + AI explanation with Pro

20. Which term means: "exposing an internal object key (e.g. /account?id=123) without authorization checks, a form of broken access control"?

Mid
  1. A.Cross-Site Scripting (XSS)
  2. B.Software and Data Integrity Failures
  3. C.Broken Access Control
  4. D.Insecure Direct Object Reference (IDOR)

Answer + AI explanation with Pro

21. Which statement is correct?

Mid
  1. A.Insecure Direct Object Reference (IDOR) — binding client-supplied input to object fields the user should not control (e.g. setting isAdmin=true)
  2. B.Insecure Direct Object Reference (IDOR) — exposing an internal object key (e.g. /account?id=123) without authorization checks, a form of broken access control
  3. C.Insecure Direct Object Reference (IDOR) — injecting OS commands through unsanitized input passed to a system shell
  4. D.Insecure Direct Object Reference (IDOR) — insufficient logging, detection, or alerting that delays breach discovery and response

Answer + AI explanation with Pro

22. What is Server-Side Request Forgery (SSRF)?

Mid
  1. A.exposing an internal object key (e.g. /account?id=123) without authorization checks, a form of broken access control
  2. B.tricking the server into making requests to attacker-chosen internal or external URLs; added to Top 10 in 2021
  3. C.trusting code, updates, or CI/CD pipelines without verifying integrity (e.g. unsigned updates, insecure deserialization)
  4. D.abusing an XML parser that resolves external entities to read files or reach internal systems

Answer + AI explanation with Pro

23. Which term means: "tricking the server into making requests to attacker-chosen internal or external URLs; added to Top 10 in 2021"?

Mid
  1. A.Cross-Site Scripting (XSS)
  2. B.Insecure Direct Object Reference (IDOR)
  3. C.Server-Side Request Forgery (SSRF)
  4. D.Vulnerable and Outdated Components

Answer + AI explanation with Pro

24. Which statement is correct?

Mid
  1. A.Server-Side Request Forgery (SSRF) — tricking the server into making requests to attacker-chosen internal or external URLs; added to Top 10 in 2021
  2. B.Server-Side Request Forgery (SSRF) — using libraries or frameworks with known vulnerabilities or that are unsupported/unpatched
  3. C.Server-Side Request Forgery (SSRF) — SQL injection inferred from boolean or timing behavior when no direct output is returned
  4. D.Server-Side Request Forgery (SSRF) — XSS where the malicious script is persisted server-side and served to every visitor

Answer + AI explanation with Pro

25. What is Vulnerable and Outdated Components?

Mid
  1. A.SQL injection inferred from boolean or timing behavior when no direct output is returned
  2. B.using libraries or frameworks with known vulnerabilities or that are unsupported/unpatched
  3. C.unvalidated redirect parameter that sends users to an attacker-chosen external site
  4. D.trusting code, updates, or CI/CD pipelines without verifying integrity (e.g. unsigned updates, insecure deserialization)

Answer + AI explanation with Pro

26. Which term means: "using libraries or frameworks with known vulnerabilities or that are unsupported/unpatched"?

Mid
  1. A.Server-Side Request Forgery (SSRF)
  2. B.Identification and Authentication Failures
  3. C.Blind SQL injection
  4. D.Vulnerable and Outdated Components

Answer + AI explanation with Pro

27. Which statement is correct?

Mid
  1. A.Vulnerable and Outdated Components — using libraries or frameworks with known vulnerabilities or that are unsupported/unpatched
  2. B.Vulnerable and Outdated Components — trusting code, updates, or CI/CD pipelines without verifying integrity (e.g. unsigned updates, insecure deserialization)
  3. C.Vulnerable and Outdated Components — exposing an internal object key (e.g. /account?id=123) without authorization checks, a form of broken access control
  4. D.Vulnerable and Outdated Components — abusing an XML parser that resolves external entities to read files or reach internal systems

Answer + AI explanation with Pro

28. What is Identification and Authentication Failures?

Mid
  1. A.insufficient logging, detection, or alerting that delays breach discovery and response
  2. B.XSS where the malicious script is persisted server-side and served to every visitor
  3. C.exposing an internal object key (e.g. /account?id=123) without authorization checks, a form of broken access control
  4. D.weaknesses like credential stuffing, weak passwords, or broken session management

Answer + AI explanation with Pro

29. Which term means: "weaknesses like credential stuffing, weak passwords, or broken session management"?

Mid
  1. A.Open redirect
  2. B.Software and Data Integrity Failures
  3. C.Identification and Authentication Failures
  4. D.Mass Assignment

Answer + AI explanation with Pro

30. Which statement is correct?

Mid
  1. A.Identification and Authentication Failures — weaknesses like credential stuffing, weak passwords, or broken session management
  2. B.Identification and Authentication Failures — abusing an XML parser that resolves external entities to read files or reach internal systems
  3. C.Identification and Authentication Failures — insufficient logging, detection, or alerting that delays breach discovery and response
  4. D.Identification and Authentication Failures — using libraries or frameworks with known vulnerabilities or that are unsupported/unpatched

Answer + AI explanation with Pro

Showing 30 of 63 AppSec · OWASP Top 10 questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every AppSec · OWASP Top 10 question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers