Ethical › Module 14 › Lesson 5
Quiz — Web Applications
10 APPLY questions on app methodology and scope.
Opening
Web applications — Module Quiz
Ten APPLY items on the sentences this module refused to collapse: the app surface is input, authentication, session, and access control; OWASP is a builder checklist on a system YOU own, not a hunting menu; deep SQLi/XSS live in Topic 10 (Module 15 names string-built SQL next) — this path does not paste exploit payloads; authorized testing is YOUR app, a lab YOU run locally, or a bug bounty whose policy YOU actually read; public DVWA copies you do not own are random sites; default is YOUR app or a localhost demo; fix patterns are server allowlist validation, contextual encoding, and authZ on every object — hide-URL is not access control; the lab artifact is $HOME/cyberlium-lab/app-route-map.txt chmod 600 (HOST 127.0.0.1 or YOUR repo). Cyberlium’s notes (app-surface, authorized-scope, fix-patterns, app-route-map) chmod 600. sqlmap, gobuster-against-campus, unread bounty, public DVWA, café portals, and payload gists are all failing answers even when they look “more CEH.” This path is original Cyberlium teaching mapped to the CEH v13 web-applications domain — not official EC-Council training, not a certification, not exam dumps. Wrong answers still teach. Empty ethics lines fail. Next after this quiz is Why String-Built SQL Breaks: the query becomes attacker-controlled text — mechanism plus parameterized queries as the fix, still no live SQLi against others. Topic 10 remains the deep injection lab path.
Knowledge Check
APPLY: A classmate wants to paste a “classic SQLi” into the school search box “because Module 14 is hacking web applications.” What are the named lanes, and what do you do?
Multiple choice
Knowledge Check
APPLY: True or False: This module should include live XSS and union-select strings, and “I was practicing CEH” covers firing them at a café portal.
True or False
Knowledge Check
APPLY: How should you use OWASP Top 10 in this Cyberlium module?
Multiple choice
Knowledge Check
APPLY: A teammate pastes an “online DVWA” URL and says it is the assigned lab. What is authorized?
Multiple choice
Knowledge Check
APPLY: Select statements that match authorized application testing in this course. (Select 2)
Select all that apply
Knowledge Check
APPLY: You have not opened a bounty policy. Which sentence is true?
Multiple choice
Knowledge Check
APPLY: True or False: Hiding /admin in the UI and trusting an isAdmin hidden field is enough authorization.
True or False
Knowledge Check
APPLY: Which trio is the Module 14 fix pattern, and where does payload depth live?
Multiple choice
Knowledge Check
APPLY: You ran the Lesson 4 lab. Which completion matches ethics and hygiene?
Multiple choice
Knowledge Check
APPLY: You carry Module 14 into Module 15. Which pairing is true, and what opens after this quiz?
Multiple choice
Knowledge Check
APPLY: curl of http://192.168.0.1/ shows a home router login (TP-Link / Netgear / Huawei / "Router Admin"). Is that DEMO in scope as a hacking target?
Multiple choice
Answer all 11 knowledge checks to continue. (0/11 answered)