63 AppSec · OWASP Top 10 questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.
Free to start: the 2-minute IT readiness check — six questions and a result.
A.injecting SQL via unsanitized input to alter the meaning of a database query
B.XSS where the malicious script is persisted server-side and served to every visitor
C.weak, missing, or misused cryptography that exposes sensitive data (renamed from Sensitive Data Exposure)
D.flaw where untrusted input is interpreted as part of a command or query (e.g. SQL, OS, LDAP)
Answer + AI explanation with Pro
2. Which term means: "flaw where untrusted input is interpreted as part of a command or query (e.g. SQL, OS, LDAP)"?
Junior
A.Blind SQL injection
B.Software and Data Integrity Failures
C.Injection
D.Server-Side Request Forgery (SSRF)
Answer + AI explanation with Pro
3. Which statement is correct?
Junior
A.Injection — flaw where untrusted input is interpreted as part of a command or query (e.g. SQL, OS, LDAP)
B.Injection — tricking the server into making requests to attacker-chosen internal or external URLs; added to Top 10 in 2021
C.Injection — insecure default settings, verbose errors, or unpatched features that expose the application
D.Injection — injecting properties into JavaScript Object.prototype to alter app behavior or escalate to RCE
Answer + AI explanation with Pro
4. What is SQL Injection?
Junior
A.failure to enforce restrictions so users can act outside their intended permissions; #1 in OWASP Top 10 2021
B.injecting SQL via unsanitized input to alter the meaning of a database query
C.flaw where untrusted input is interpreted as part of a command or query (e.g. SQL, OS, LDAP)
D.insufficient logging, detection, or alerting that delays breach discovery and response
Answer + AI explanation with Pro
5. Which term means: "injecting SQL via unsanitized input to alter the meaning of a database query"?
Junior
A.Cryptographic Failures
B.SQL Injection
C.Cross-Site Scripting (XSS)
D.DOM-based XSS
Answer + AI explanation with Pro
6. Which statement is correct?
Junior
A.SQL Injection — injecting SQL via unsanitized input to alter the meaning of a database query
B.SQL Injection — XSS where the malicious script is persisted server-side and served to every visitor
C.SQL Injection — weaknesses like credential stuffing, weak passwords, or broken session management
D.SQL Injection — binding client-supplied input to object fields the user should not control (e.g. setting isAdmin=true)
Answer + AI explanation with Pro
7. What is Cross-Site Scripting (XSS)?
Junior
A.weak, missing, or misused cryptography that exposes sensitive data (renamed from Sensitive Data Exposure)
B.injecting properties into JavaScript Object.prototype to alter app behavior or escalate to RCE
C.weaknesses like credential stuffing, weak passwords, or broken session management
D.injecting attacker-controlled script that executes in another user's browser session
Answer + AI explanation with Pro
8. Which term means: "injecting attacker-controlled script that executes in another user's browser session"?
Junior
A.Vulnerable and Outdated Components
B.Cross-Site Scripting (XSS)
C.Injection
D.Identification and Authentication Failures
Answer + AI explanation with Pro
9. Which statement is correct?
Junior
A.Cross-Site Scripting (XSS) — using libraries or frameworks with known vulnerabilities or that are unsupported/unpatched
B.Cross-Site Scripting (XSS) — injecting attacker-controlled script that executes in another user's browser session
C.Cross-Site Scripting (XSS) — exposing an internal object key (e.g. /account?id=123) without authorization checks, a form of broken access control
D.Cross-Site Scripting (XSS) — insufficient logging, detection, or alerting that delays breach discovery and response
Answer + AI explanation with Pro
10. What is Broken Access Control?
Junior
A.insufficient logging, detection, or alerting that delays breach discovery and response
B.injecting SQL via unsanitized input to alter the meaning of a database query
C.flaw where untrusted input is interpreted as part of a command or query (e.g. SQL, OS, LDAP)
D.failure to enforce restrictions so users can act outside their intended permissions; #1 in OWASP Top 10 2021
Answer + AI explanation with Pro
11. Which term means: "failure to enforce restrictions so users can act outside their intended permissions; #1 in OWASP Top 10 2021"?
Junior
A.Command injection
B.Blind SQL injection
C.Open redirect
D.Broken Access Control
Answer + AI explanation with Pro
12. Which statement is correct?
Junior
A.Broken Access Control — weaknesses like credential stuffing, weak passwords, or broken session management
B.Broken Access Control — failure to enforce restrictions so users can act outside their intended permissions; #1 in OWASP Top 10 2021
C.Broken Access Control — SQL injection inferred from boolean or timing behavior when no direct output is returned
D.Broken Access Control — injecting OS commands through unsanitized input passed to a system shell
Answer + AI explanation with Pro
13. What is Security Misconfiguration?
Junior
A.XSS where the malicious script is persisted server-side and served to every visitor
B.injecting SQL via unsanitized input to alter the meaning of a database query
C.insecure default settings, verbose errors, or unpatched features that expose the application
D.failure to enforce restrictions so users can act outside their intended permissions; #1 in OWASP Top 10 2021
Answer + AI explanation with Pro
14. Which term means: "insecure default settings, verbose errors, or unpatched features that expose the application"?
Junior
A.Server-Side Request Forgery (SSRF)
B.DOM-based XSS
C.Security Misconfiguration
D.Identification and Authentication Failures
Answer + AI explanation with Pro
15. Which statement is correct?
Junior
A.Security Misconfiguration — using libraries or frameworks with known vulnerabilities or that are unsupported/unpatched
B.Security Misconfiguration — unvalidated redirect parameter that sends users to an attacker-chosen external site
C.Security Misconfiguration — injecting properties into JavaScript Object.prototype to alter app behavior or escalate to RCE
D.Security Misconfiguration — insecure default settings, verbose errors, or unpatched features that expose the application
Answer + AI explanation with Pro
16. What is Cryptographic Failures?
Junior
A.XSS executed entirely client-side when JavaScript writes untrusted data into the DOM
B.weak, missing, or misused cryptography that exposes sensitive data (renamed from Sensitive Data Exposure)
C.abusing an XML parser that resolves external entities to read files or reach internal systems
D.binding client-supplied input to object fields the user should not control (e.g. setting isAdmin=true)
Answer + AI explanation with Pro
17. Which term means: "weak, missing, or misused cryptography that exposes sensitive data (renamed from Sensitive Data Exposure)"?
Junior
A.Blind SQL injection
B.Cryptographic Failures
C.Security Logging and Monitoring Failures
D.SQL Injection
Answer + AI explanation with Pro
18. Which statement is correct?
Junior
A.Cryptographic Failures — exposing an internal object key (e.g. /account?id=123) without authorization checks, a form of broken access control
B.Cryptographic Failures — injecting attacker-controlled script that executes in another user's browser session
C.Cryptographic Failures — weak, missing, or misused cryptography that exposes sensitive data (renamed from Sensitive Data Exposure)
D.Cryptographic Failures — injecting OS commands through unsanitized input passed to a system shell
Answer + AI explanation with Pro
19. What is Insecure Direct Object Reference (IDOR)?
Mid
A.weak, missing, or misused cryptography that exposes sensitive data (renamed from Sensitive Data Exposure)
B.injecting properties into JavaScript Object.prototype to alter app behavior or escalate to RCE
C.exposing an internal object key (e.g. /account?id=123) without authorization checks, a form of broken access control
D.weaknesses like credential stuffing, weak passwords, or broken session management
Answer + AI explanation with Pro
20. Which term means: "exposing an internal object key (e.g. /account?id=123) without authorization checks, a form of broken access control"?
Mid
A.Cross-Site Scripting (XSS)
B.Software and Data Integrity Failures
C.Broken Access Control
D.Insecure Direct Object Reference (IDOR)
Answer + AI explanation with Pro
21. Which statement is correct?
Mid
A.Insecure Direct Object Reference (IDOR) — binding client-supplied input to object fields the user should not control (e.g. setting isAdmin=true)
B.Insecure Direct Object Reference (IDOR) — exposing an internal object key (e.g. /account?id=123) without authorization checks, a form of broken access control
C.Insecure Direct Object Reference (IDOR) — injecting OS commands through unsanitized input passed to a system shell
D.Insecure Direct Object Reference (IDOR) — insufficient logging, detection, or alerting that delays breach discovery and response
Answer + AI explanation with Pro
22. What is Server-Side Request Forgery (SSRF)?
Mid
A.exposing an internal object key (e.g. /account?id=123) without authorization checks, a form of broken access control
B.tricking the server into making requests to attacker-chosen internal or external URLs; added to Top 10 in 2021
C.trusting code, updates, or CI/CD pipelines without verifying integrity (e.g. unsigned updates, insecure deserialization)
D.abusing an XML parser that resolves external entities to read files or reach internal systems
Answer + AI explanation with Pro
23. Which term means: "tricking the server into making requests to attacker-chosen internal or external URLs; added to Top 10 in 2021"?
Mid
A.Cross-Site Scripting (XSS)
B.Insecure Direct Object Reference (IDOR)
C.Server-Side Request Forgery (SSRF)
D.Vulnerable and Outdated Components
Answer + AI explanation with Pro
24. Which statement is correct?
Mid
A.Server-Side Request Forgery (SSRF) — tricking the server into making requests to attacker-chosen internal or external URLs; added to Top 10 in 2021
B.Server-Side Request Forgery (SSRF) — using libraries or frameworks with known vulnerabilities or that are unsupported/unpatched
C.Server-Side Request Forgery (SSRF) — SQL injection inferred from boolean or timing behavior when no direct output is returned
D.Server-Side Request Forgery (SSRF) — XSS where the malicious script is persisted server-side and served to every visitor
Answer + AI explanation with Pro
25. What is Vulnerable and Outdated Components?
Mid
A.SQL injection inferred from boolean or timing behavior when no direct output is returned
B.using libraries or frameworks with known vulnerabilities or that are unsupported/unpatched
C.unvalidated redirect parameter that sends users to an attacker-chosen external site
D.trusting code, updates, or CI/CD pipelines without verifying integrity (e.g. unsigned updates, insecure deserialization)
Answer + AI explanation with Pro
26. Which term means: "using libraries or frameworks with known vulnerabilities or that are unsupported/unpatched"?
Mid
A.Server-Side Request Forgery (SSRF)
B.Identification and Authentication Failures
C.Blind SQL injection
D.Vulnerable and Outdated Components
Answer + AI explanation with Pro
27. Which statement is correct?
Mid
A.Vulnerable and Outdated Components — using libraries or frameworks with known vulnerabilities or that are unsupported/unpatched
B.Vulnerable and Outdated Components — trusting code, updates, or CI/CD pipelines without verifying integrity (e.g. unsigned updates, insecure deserialization)
C.Vulnerable and Outdated Components — exposing an internal object key (e.g. /account?id=123) without authorization checks, a form of broken access control
D.Vulnerable and Outdated Components — abusing an XML parser that resolves external entities to read files or reach internal systems
Answer + AI explanation with Pro
28. What is Identification and Authentication Failures?
Mid
A.insufficient logging, detection, or alerting that delays breach discovery and response
B.XSS where the malicious script is persisted server-side and served to every visitor
C.exposing an internal object key (e.g. /account?id=123) without authorization checks, a form of broken access control
D.weaknesses like credential stuffing, weak passwords, or broken session management
Answer + AI explanation with Pro
29. Which term means: "weaknesses like credential stuffing, weak passwords, or broken session management"?
Mid
A.Open redirect
B.Software and Data Integrity Failures
C.Identification and Authentication Failures
D.Mass Assignment
Answer + AI explanation with Pro
30. Which statement is correct?
Mid
A.Identification and Authentication Failures — weaknesses like credential stuffing, weak passwords, or broken session management
B.Identification and Authentication Failures — abusing an XML parser that resolves external entities to read files or reach internal systems
C.Identification and Authentication Failures — insufficient logging, detection, or alerting that delays breach discovery and response
D.Identification and Authentication Failures — using libraries or frameworks with known vulnerabilities or that are unsupported/unpatched
Answer + AI explanation with Pro
Showing 30 of 63 AppSec · OWASP Top 10 questions — the full set, with answers, explanations and an AI tutor on every question, is inside.
Free to start
Start with a free readiness check
Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every AppSec · OWASP Top 10 question come with Pro.