Web Security Headers interview questions

42 Web Security Headers questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What is Content-Security-Policy (CSP)?

Junior
  1. A.header controlling how much referrer information browsers send with requests
  2. B.CSP mode that reports violations without blocking, used to tune a policy before enforcing
  3. C.Cross-Origin Resource Sharing, headers that relax the same-origin policy in a controlled way
  4. D.header restricting which sources of scripts, styles, and other content a page may load

Answer + AI explanation with Pro

2. Which term means: "header restricting which sources of scripts, styles, and other content a page may load"?

Junior
  1. A.X-Content-Type-Options
  2. B.Content-Security-Policy (CSP)
  3. C.SameSite cookie attribute
  4. D.Same-origin policy

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.Content-Security-Policy (CSP) — header set to nosniff to stop browsers from MIME-sniffing responses to a different content type
  2. B.Content-Security-Policy (CSP) — header restricting which sources of scripts, styles, and other content a page may load
  3. C.Content-Security-Policy (CSP) — integrity attribute letting browsers verify a fetched script/style matches an expected hash
  4. D.Content-Security-Policy (CSP) — HSTS header instructing browsers to only connect over HTTPS for a set duration

Answer + AI explanation with Pro

4. What is X-Frame-Options?

Junior
  1. A.header controlling whether a page can be framed, defending against clickjacking
  2. B.cookie flag (Lax/Strict/None) limiting cross-site sending to mitigate CSRF
  3. C.header restricting which sources of scripts, styles, and other content a page may load
  4. D.HSTS header instructing browsers to only connect over HTTPS for a set duration

Answer + AI explanation with Pro

5. Which term means: "header controlling whether a page can be framed, defending against clickjacking"?

Junior
  1. A.Subresource Integrity (SRI)
  2. B.X-Frame-Options
  3. C.Strict-Transport-Security
  4. D.Same-origin policy

Answer + AI explanation with Pro

6. Which statement is correct?

Junior
  1. A.X-Frame-Options — header controlling how much referrer information browsers send with requests
  2. B.X-Frame-Options — header controlling whether a page can be framed, defending against clickjacking
  3. C.X-Frame-Options — Cross-Origin Resource Sharing, headers that relax the same-origin policy in a controlled way
  4. D.X-Frame-Options — cookie flag (Lax/Strict/None) limiting cross-site sending to mitigate CSRF

Answer + AI explanation with Pro

7. What is Strict-Transport-Security?

Junior
  1. A.flag ensuring a cookie is only sent over HTTPS connections
  2. B.HSTS header instructing browsers to only connect over HTTPS for a set duration
  3. C.CSP mode that reports violations without blocking, used to tune a policy before enforcing
  4. D.browser rule restricting how a document from one origin can interact with resources from another

Answer + AI explanation with Pro

8. Which term means: "HSTS header instructing browsers to only connect over HTTPS for a set duration"?

Junior
  1. A.Secure cookie flag
  2. B.CSP nonce
  3. C.Strict-Transport-Security
  4. D.X-Frame-Options

Answer + AI explanation with Pro

9. Which statement is correct?

Junior
  1. A.Strict-Transport-Security — CSP mode that reports violations without blocking, used to tune a policy before enforcing
  2. B.Strict-Transport-Security — Cross-Origin Resource Sharing, headers that relax the same-origin policy in a controlled way
  3. C.Strict-Transport-Security — header controlling whether a page can be framed, defending against clickjacking
  4. D.Strict-Transport-Security — HSTS header instructing browsers to only connect over HTTPS for a set duration

Answer + AI explanation with Pro

10. What is X-Content-Type-Options?

Junior
  1. A.flag preventing JavaScript from reading a cookie, reducing token theft via XSS
  2. B.header set to nosniff to stop browsers from MIME-sniffing responses to a different content type
  3. C.header controlling which browser features (camera, geolocation, etc.) a page may use
  4. D.per-response random token allowing only matching inline scripts to execute under CSP

Answer + AI explanation with Pro

11. Which term means: "header set to nosniff to stop browsers from MIME-sniffing responses to a different content type"?

Junior
  1. A.Content-Security-Policy (CSP)
  2. B.X-Content-Type-Options
  3. C.Permissions-Policy
  4. D.CSP report-only mode

Answer + AI explanation with Pro

12. Which statement is correct?

Junior
  1. A.X-Content-Type-Options — integrity attribute letting browsers verify a fetched script/style matches an expected hash
  2. B.X-Content-Type-Options — browser rule restricting how a document from one origin can interact with resources from another
  3. C.X-Content-Type-Options — cookie flag (Lax/Strict/None) limiting cross-site sending to mitigate CSRF
  4. D.X-Content-Type-Options — header set to nosniff to stop browsers from MIME-sniffing responses to a different content type

Answer + AI explanation with Pro

13. What is Referrer-Policy?

Junior
  1. A.header controlling how much referrer information browsers send with requests
  2. B.integrity attribute letting browsers verify a fetched script/style matches an expected hash
  3. C.flag ensuring a cookie is only sent over HTTPS connections
  4. D.Cross-Origin Resource Sharing, headers that relax the same-origin policy in a controlled way

Answer + AI explanation with Pro

14. Which term means: "header controlling how much referrer information browsers send with requests"?

Junior
  1. A.Secure cookie flag
  2. B.CSP nonce
  3. C.Subresource Integrity (SRI)
  4. D.Referrer-Policy

Answer + AI explanation with Pro

15. Which statement is correct?

Junior
  1. A.Referrer-Policy — header controlling which browser features (camera, geolocation, etc.) a page may use
  2. B.Referrer-Policy — browser rule restricting how a document from one origin can interact with resources from another
  3. C.Referrer-Policy — flag ensuring a cookie is only sent over HTTPS connections
  4. D.Referrer-Policy — header controlling how much referrer information browsers send with requests

Answer + AI explanation with Pro

16. What is SameSite cookie attribute?

Mid
  1. A.cookie flag (Lax/Strict/None) limiting cross-site sending to mitigate CSRF
  2. B.browser rule restricting how a document from one origin can interact with resources from another
  3. C.flag ensuring a cookie is only sent over HTTPS connections
  4. D.header controlling how much referrer information browsers send with requests

Answer + AI explanation with Pro

17. Which term means: "cookie flag (Lax/Strict/None) limiting cross-site sending to mitigate CSRF"?

Mid
  1. A.X-Frame-Options
  2. B.Permissions-Policy
  3. C.X-Content-Type-Options
  4. D.SameSite cookie attribute

Answer + AI explanation with Pro

18. Which statement is correct?

Mid
  1. A.SameSite cookie attribute — cookie flag (Lax/Strict/None) limiting cross-site sending to mitigate CSRF
  2. B.SameSite cookie attribute — per-response random token allowing only matching inline scripts to execute under CSP
  3. C.SameSite cookie attribute — flag ensuring a cookie is only sent over HTTPS connections
  4. D.SameSite cookie attribute — HSTS header instructing browsers to only connect over HTTPS for a set duration

Answer + AI explanation with Pro

19. What is HttpOnly cookie flag?

Mid
  1. A.header controlling which browser features (camera, geolocation, etc.) a page may use
  2. B.per-response random token allowing only matching inline scripts to execute under CSP
  3. C.browser rule restricting how a document from one origin can interact with resources from another
  4. D.flag preventing JavaScript from reading a cookie, reducing token theft via XSS

Answer + AI explanation with Pro

20. Which term means: "flag preventing JavaScript from reading a cookie, reducing token theft via XSS"?

Mid
  1. A.X-Content-Type-Options
  2. B.Strict-Transport-Security
  3. C.HttpOnly cookie flag
  4. D.X-Frame-Options

Answer + AI explanation with Pro

21. Which statement is correct?

Mid
  1. A.HttpOnly cookie flag — header controlling how much referrer information browsers send with requests
  2. B.HttpOnly cookie flag — integrity attribute letting browsers verify a fetched script/style matches an expected hash
  3. C.HttpOnly cookie flag — flag preventing JavaScript from reading a cookie, reducing token theft via XSS
  4. D.HttpOnly cookie flag — flag ensuring a cookie is only sent over HTTPS connections

Answer + AI explanation with Pro

22. What is Secure cookie flag?

Mid
  1. A.header controlling which browser features (camera, geolocation, etc.) a page may use
  2. B.flag ensuring a cookie is only sent over HTTPS connections
  3. C.integrity attribute letting browsers verify a fetched script/style matches an expected hash
  4. D.header set to nosniff to stop browsers from MIME-sniffing responses to a different content type

Answer + AI explanation with Pro

23. Which term means: "flag ensuring a cookie is only sent over HTTPS connections"?

Mid
  1. A.HttpOnly cookie flag
  2. B.Permissions-Policy
  3. C.Secure cookie flag
  4. D.Strict-Transport-Security

Answer + AI explanation with Pro

24. Which statement is correct?

Mid
  1. A.Secure cookie flag — cookie flag (Lax/Strict/None) limiting cross-site sending to mitigate CSRF
  2. B.Secure cookie flag — flag ensuring a cookie is only sent over HTTPS connections
  3. C.Secure cookie flag — header set to nosniff to stop browsers from MIME-sniffing responses to a different content type
  4. D.Secure cookie flag — header controlling whether a page can be framed, defending against clickjacking

Answer + AI explanation with Pro

25. What is CORS?

Mid
  1. A.header controlling whether a page can be framed, defending against clickjacking
  2. B.HSTS header instructing browsers to only connect over HTTPS for a set duration
  3. C.Cross-Origin Resource Sharing, headers that relax the same-origin policy in a controlled way
  4. D.header restricting which sources of scripts, styles, and other content a page may load

Answer + AI explanation with Pro

26. Which term means: "Cross-Origin Resource Sharing, headers that relax the same-origin policy in a controlled way"?

Mid
  1. A.X-Frame-Options
  2. B.HttpOnly cookie flag
  3. C.Strict-Transport-Security
  4. D.CORS

Answer + AI explanation with Pro

27. Which statement is correct?

Mid
  1. A.CORS — per-response random token allowing only matching inline scripts to execute under CSP
  2. B.CORS — browser rule restricting how a document from one origin can interact with resources from another
  3. C.CORS — Cross-Origin Resource Sharing, headers that relax the same-origin policy in a controlled way
  4. D.CORS — header controlling how much referrer information browsers send with requests

Answer + AI explanation with Pro

28. What is Permissions-Policy?

Mid
  1. A.browser rule restricting how a document from one origin can interact with resources from another
  2. B.header controlling which browser features (camera, geolocation, etc.) a page may use
  3. C.HSTS header instructing browsers to only connect over HTTPS for a set duration
  4. D.integrity attribute letting browsers verify a fetched script/style matches an expected hash

Answer + AI explanation with Pro

29. Which term means: "header controlling which browser features (camera, geolocation, etc.) a page may use"?

Mid
  1. A.CSP report-only mode
  2. B.Permissions-Policy
  3. C.HttpOnly cookie flag
  4. D.CSP nonce

Answer + AI explanation with Pro

30. Which statement is correct?

Mid
  1. A.Permissions-Policy — header controlling which browser features (camera, geolocation, etc.) a page may use
  2. B.Permissions-Policy — browser rule restricting how a document from one origin can interact with resources from another
  3. C.Permissions-Policy — header controlling how much referrer information browsers send with requests
  4. D.Permissions-Policy — cookie flag (Lax/Strict/None) limiting cross-site sending to mitigate CSRF

Answer + AI explanation with Pro

Showing 30 of 42 Web Security Headers questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Web Security Headers question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers