Courseiva

CCNA Web Communication Security Questions

12 questions · Web Communication Security · All types, answers revealed

1
MCQhard

A security analyst is examining a web application that uses HTTP Strict Transport Security (HSTS). The analyst notices that the HSTS header is only sent on HTTPS responses and includes the 'preload' directive. Which additional measure must be taken to ensure the domain is included in browser preload lists?

A.Submit the domain to the HSTS preload list maintained by Google, and ensure the header includes 'includeSubDomains' and a max-age of at least one year.
B.Ensure the HSTS header is sent with a max-age of at least six months and includes the 'preload' directive, then submit the domain to the preload list.
C.Configure the server to redirect all HTTP requests to HTTPS with a 301 status code and include the HSTS header in the redirect response.
D.Add the 'preload' directive to the HSTS header and wait for browsers to automatically discover and add the domain to their preload lists.
AnswerA

To be included in browser HSTS preload lists, the domain must be submitted to the preload list service (e.g., hstspreload.org) and meet specific requirements: the HSTS header must include 'includeSubDomains', 'preload', and a max-age of at least 31536000 seconds (one year). The preload directive signals intent, but submission is a separate manual step. This ensures the domain is hardcoded into browsers, providing protection even on the first visit.

Why this answer

To preload HSTS, the domain must meet strict criteria: the HSTS header must include 'includeSubDomains', 'preload', and a max-age of at least one year. The 'preload' directive alone does not trigger automatic inclusion; the domain must be submitted to the preload list service. Once accepted, browsers hardcode the domain, enforcing HTTPS even on the first visit.

This prevents SSL stripping attacks during initial connections.

Exam trap

The trap here is assuming that adding the 'preload' directive to the HSTS header is sufficient for browser preloading, when in fact manual submission and specific header requirements must be satisfied.

2
Multi-Selectmedium

A security engineer is configuring a web server to enforce secure communication and prevent man-in-the-middle attacks. The engineer wants to implement HTTP Strict Transport Security (HSTS) and ensure that it is properly deployed. Which TWO of the following are required for HSTS to be effective? (Choose two.)

Select 2 answers
A.The HSTS header must include the includeSubDomains directive to protect all subdomains.
B.The HSTS header must be served over a valid HTTPS connection with a trusted certificate.
C.The server must include the Strict-Transport-Security header in HTTPS responses.
D.The server must be configured to support TLS 1.2 or higher for HSTS to function.
E.The server must redirect all HTTP requests to HTTPS before the HSTS header is processed.
AnswersB, C

For the browser to accept and enforce HSTS, the header must be received over HTTPS with a certificate that the browser trusts. If the certificate is invalid or self-signed, the browser will not process the HSTS header, and the policy will not be applied. Therefore, a valid HTTPS connection is necessary for HSTS to be effective.

Why this answer

HSTS is enabled when the server sends the Strict-Transport-Security header over a trusted HTTPS connection. The browser then enforces HTTPS for future requests. A valid certificate is necessary for the browser to accept the header.

Redirects and includeSubDomains are optional enhancements, and specific TLS versions are not mandated by HSTS itself. Therefore, the required elements are the header over HTTPS and a trusted certificate.

Exam trap

The trap here is assuming that HTTP-to-HTTPS redirects are required for HSTS, when in fact HSTS bypasses HTTP entirely after the initial header is received.

3
MCQhard

A developer wants to prevent sensitive cookies from being transmitted over unencrypted HTTP connections. Which cookie attribute is specifically designed to enforce this requirement?

A.HttpOnly
B.SameSite=Strict
C.Secure
D.Path=/secure
AnswerC

The Secure flag instructs the browser to restrict the cookie transmission to encrypted (HTTPS) connections only. This is the primary mechanism for ensuring that sensitive session identifiers are not exposed in plaintext during network transit, providing a necessary layer of protection against sniffing and interception of data.

Why this answer

The Secure attribute is a critical security control for web applications. When a cookie is marked as Secure, the browser will only transmit that cookie if the request is being made over an encrypted connection, such as HTTPS. This prevents session tokens or sensitive data from being intercepted in cleartext via man-in-the-middle attacks, ensuring that transport-layer security is effectively utilized for all sensitive session-based interactions.

Exam trap

Candidates mix up the Secure attribute with HttpOnly, mistakenly thinking HttpOnly enforces encryption during transit across the network.

4
MCQmedium

A security analyst is reviewing a web application that allows users to upload profile pictures. The application accepts files with .jpg and .png extensions, but the analyst discovers that an attacker can upload a file named 'avatar.php.jpg' and then access it directly via a URL. The server executes the file as PHP. Which security control would most directly prevent this type of attack?

A.Store uploaded files outside the web root and serve them via a handler that validates file content.
B.Implement a strict Content Security Policy (CSP) that disallows inline scripts.
C.Enforce HTTPS for all upload and download requests to prevent man-in-the-middle attacks.
D.Set the 'secure' attribute on session cookies to ensure they are only sent over encrypted connections.
AnswerA

Storing files outside the web root prevents direct URL access, and a validating handler ensures only safe file types are served. This combination stops the server from executing the uploaded file, because the file is never placed in a location where the web server would interpret it as code. It directly mitigates the vulnerability by removing the execution path and enforcing content validation.

Why this answer

The vulnerability arises because the server executes uploaded files based on their extension or content. Storing files outside the web root and serving them through a validating handler prevents direct execution and ensures only safe content is delivered. This approach directly addresses the root cause, whereas other controls like CSP, HTTPS, or cookie flags do not stop server-side code execution.

Exam trap

The trap here is assuming that client-side controls like CSP or transport encryption can mitigate server-side file execution vulnerabilities.

5
MCQmedium

An administrator observes that internal users are receiving certificate warnings when accessing a new internal web application. The organization uses an internal Certificate Authority (CA). What is the primary cause of this behavior?

A.The server certificate has expired, triggering a validity date error in the browser.
B.The web server failed to send the intermediate certificate in the handshake process.
C.The internal Root CA certificate is not installed in the client's local trust store.
D.The web application is utilizing an outdated TLS version that browsers no longer support.
AnswerC

Web browsers rely on the local certificate store to validate the identity of web servers. If the issuing CA's root certificate is not present in the user's trusted root certification authorities store, the browser will signal that the site's identity cannot be verified, resulting in a security warning.

Why this answer

Certificate warnings occur when a client cannot establish a chain of trust back to a trusted Root CA. In internal environments, the internal CA certificate must be explicitly imported into the client's trusted root store. Without this root trust, the browser cannot verify the digital signature of the server's certificate, resulting in a trust error.

This is a fundamental concept in PKI management for enterprise web security.

Exam trap

Candidates often blame expired server certificates or incorrect cipher suites rather than recognizing missing trust stores for internal CAs.

6
MCQeasy

During a web application audit, you determine that the server is vulnerable to a 'Slowloris' attack. What is the most likely symptom of this attack on the web server?

A.Complete server crash due to memory corruption
B.Database downtime caused by excessive query volume
C.Exhaustion of available connection slots
D.Unauthorized access to the application root directory
AnswerC

Slowloris works by opening many connections and sending headers very slowly, never finishing the request. Since the server keeps these connections open while waiting for the full request, it eventually reaches its maximum connection limit, preventing any new legitimate users from connecting to the application.

Why this answer

Slowloris is a low-bandwidth Denial-of-Service (DoS) attack that keeps connections open by sending partial HTTP requests. By never completing the request headers, the server's connection pool becomes exhausted, leaving no threads available to handle legitimate users. This is a classic example of an application-layer DoS attack, which highlights the importance of configuring proper timeout settings and resource limits on web servers like Apache or Nginx.

Exam trap

Candidates often confuse Slowloris with volumetric DDoS attacks like SYN floods. They wrongly assume the symptom is bandwidth saturation, failing to realize the server remains responsive but lacks available threads for new connections.

7
MCQeasy

A security administrator is reviewing web server logs and notices a high volume of requests with different User-Agent strings, all targeting the same URL with varying query parameters. The requests appear to be attempting to inject SQL commands. Which of the following is the most effective mitigation to prevent SQL injection in this scenario?

A.Deploy a Web Application Firewall (WAF) with SQL injection signatures.
B.Implement strict input validation to allow only alphanumeric characters.
C.Encode all user input using HTML entity encoding before storing in the database.
D.Use parameterized queries (prepared statements) for all database access.
AnswerD

Parameterized queries ensure that user input is treated as data, not executable code, by separating SQL logic from data. This prevents attackers from altering the query structure, regardless of the input's content. It is the most effective and fundamental mitigation against SQL injection, as it eliminates the vulnerability at the source rather than relying on pattern matching.

Why this answer

SQL injection occurs when user input is improperly concatenated into SQL queries. Parameterized queries, also known as prepared statements, ensure that input is bound as parameters and never interpreted as SQL code. This eliminates the vulnerability entirely.

While WAFs and input validation can help, they are not as reliable or comprehensive. Therefore, using parameterized queries is the most effective mitigation.

Exam trap

The trap here is confusing input validation or encoding with proper query parameterization, which is the definitive fix for SQL injection.

8
MCQmedium

A penetration tester is reviewing the TLS configuration of an e-commerce web server. The tester observes that the server prefers the cipher suite TLS_RSA_WITH_AES_128_CBC_SHA during the handshake. Which security weakness does this cipher suite selection introduce?

A.It lacks forward secrecy because the RSA key exchange does not generate ephemeral session keys.
B.It uses AES in CBC mode, which is vulnerable to padding oracle attacks such as POODLE.
C.It uses SHA-1 for integrity, which is considered cryptographically broken for MACs.
D.It allows downgrade to export-grade cryptography because of the RSA key exchange.
AnswerA

TLS_RSA_WITH_AES_128_CBC_SHA uses static RSA key exchange, meaning the premaster secret is encrypted with the server's long-term RSA key. If an attacker records the encrypted session and later obtains the server's private key, they can decrypt all past sessions. This violates forward secrecy, a critical property for protecting historical traffic. Modern best practice mandates ECDHE or DHE cipher suites to ensure each session has unique ephemeral keys.

Why this answer

The cipher suite TLS_RSA_WITH_AES_128_CBC_SHA relies on static RSA key exchange, where the client encrypts a premaster secret with the server's public key. This means the session key is tied to the server's long-term private key. If that private key is compromised later, an attacker who recorded the encrypted session can decrypt it retroactively.

Forward secrecy requires ephemeral key exchanges like ECDHE or DHE, which generate unique session keys that are not recoverable from the long-term key.

Exam trap

The trap here is assuming that any cipher suite with AES and SHA-1 is automatically weak due to the hash algorithm, when the critical flaw is actually the static RSA key exchange lacking forward secrecy.

9
MCQhard

A security analyst is reviewing a web application's HTTP response headers and notices the following header: Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'. The analyst is concerned about the application's resilience to cross-site scripting (XSS). Which of the following best describes the security implication of this policy?

A.The policy is insecure because it allows inline scripts, which can be exploited by XSS attacks.
B.The policy is insecure because it lacks a report-uri directive, so violations cannot be monitored.
C.The policy is secure because default-src 'self' prevents loading scripts from external domains, mitigating XSS.
D.The policy is secure because it restricts scripts to the same origin and disallows inline scripts.
AnswerA

The presence of 'unsafe-inline' in the script-src directive allows the execution of inline JavaScript. This means that if an attacker can inject a <script> tag with malicious code, it will execute because the CSP does not block inline scripts. This significantly reduces the XSS mitigation that CSP would otherwise provide. Thus, the policy is insecure in this context.

Why this answer

The Content-Security-Policy header includes 'unsafe-inline' in the script-src directive, which permits inline JavaScript execution. This directly undermines CSP's ability to prevent XSS attacks, as injected inline scripts will run. The correct answer identifies that allowing inline scripts makes the policy insecure.

The other options incorrectly focus on external script restrictions or reporting, missing the critical weakness.

Exam trap

The trap here is overlooking the 'unsafe-inline' directive and assuming that 'self' alone provides strong XSS protection.

10
MCQhard

A security analyst is examining a web application that uses JSON Web Tokens (JWT) for authentication. The analyst captures a token and notices that the header contains "alg": "none". The analyst is concerned about the security of the application. Which of the following best describes the risk associated with this token?

A.The token is unsigned, allowing an attacker to modify the payload and forge valid tokens.
B.The token uses a weak signing algorithm that can be brute-forced to recover the secret key.
C.The token is vulnerable to replay attacks because it lacks an expiration claim.
D.The token is encrypted, so the contents cannot be read by an attacker.
AnswerA

When the JWT header specifies "alg": "none", it means the token has no signature. An attacker can alter the payload (e.g., change user privileges) and since there is no signature to verify, the server may accept the modified token if it does not properly reject "none" algorithms. This is a critical vulnerability that can lead to authentication bypass and privilege escalation.

Why this answer

A JWT with "alg": "none" is unsigned, meaning it has no integrity protection. An attacker can tamper with the payload and, if the server accepts such tokens, forge arbitrary claims. This can lead to authentication bypass or privilege escalation.

The correct answer identifies that the token is unsigned and can be modified. The other options mischaracterize the token as encrypted, weakly signed, or solely vulnerable to replay, missing the core issue of missing signature verification.

Exam trap

The trap here is assuming that "none" is a valid secure algorithm or that it provides some form of protection, when in reality it means the token is completely unsigned.

11
MCQeasy

A web developer is implementing a new session management system and wants to ensure that session cookies are not accessible via JavaScript to mitigate cross-site scripting (XSS) attacks. Which cookie attribute should be set?

A.SameSite
B.Domain
C.HttpOnly
D.Secure
AnswerC

The HttpOnly attribute instructs the browser to prevent client-side scripts from accessing the cookie. This directly mitigates XSS attacks that attempt to steal session cookies via document.cookie. When set, the cookie is only accessible to the server, not JavaScript. This is the correct attribute to use for the described requirement.

Why this answer

The HttpOnly attribute is specifically designed to prevent client-side scripts from accessing cookies. By setting HttpOnly, the cookie is protected from theft via XSS attacks that execute JavaScript in the victim's browser. The other attributes serve different purposes: Secure ensures HTTPS transmission, SameSite mitigates CSRF, and Domain controls cookie scope.

Only HttpOnly directly addresses the requirement.

Exam trap

The trap here is confusing the Secure attribute with HttpOnly; Secure protects transmission, not JavaScript access.

12
MCQmedium

Refer to the exhibit. Which security risk does the 'HttpOnly' flag specifically mitigate?

A.Cross-Site Request Forgery (CSRF)
B.Cross-Site Scripting (XSS) session theft
C.Man-in-the-Middle (MitM) interception
D.SQL Injection (SQLi)
AnswerB

HttpOnly prevents JavaScript from reading the cookie content. In an XSS scenario, an attacker typically tries to exfiltrate the session cookie to an external server. With the HttpOnly attribute, the browser rejects requests from scripts to read the cookie, effectively neutralizing this specific theft vector during an injection.

Why this answer

The HttpOnly flag is a vital defense against session hijacking via XSS. When this flag is enabled, the browser prevents client-side scripts, such as JavaScript, from accessing the cookie via the document.cookie object. If an attacker successfully executes an XSS attack, they cannot steal the session cookie, thereby preventing them from impersonating the user's session.

This is a core defense-in-depth practice for protecting authentication tokens in modern web applications.

Exam trap

Candidates often confuse the HttpOnly flag with the Secure flag, incorrectly believing HttpOnly prevents interception over unencrypted networks rather than preventing script access.

Ready to test yourself?

Try a timed practice session using only Web Communication Security questions.