Cyberlium

Web › Module 2 › Lesson 5

BeginnerModule 2Lesson 5/5

Quiz — Security Misconfiguration

10 APPLY on A02: defaults, headers, clickjacking, demo http://192.168.0.1/ ethics.

10 min+40 XP10 quiz
Module progress5 of 5

Opening

Security Misconfiguration — Module Quiz

Ten APPLY items on OWASP Top 10:2025 A02: insecure defaults and debug, directory listings and open surfaces, CSP/nosniff/HSTS literacy, clickjacking frame defenses, broken vs hard on HOST , $HOME/cyberlium-lab notes chmod 600.

Knowledge Check

1

APPLY: Production still serves a full stack trace and /debug. What A02 issue is that?

Multiple choice

Knowledge Check

2

APPLY: True or False: Default admin/admin is fine if the password is in the vendor docs.

True or False

Knowledge Check

3

APPLY: Directory listing shows a forgotten backup folder on YOUR lab. What do you ship?

Multiple choice

Knowledge Check

4

APPLY: Which header set best matches this module’s hard mode literacy?

Multiple choice

Knowledge Check

5

APPLY: True or False: BeEF is the assigned way to prove CSP in Cyberlium A02.

True or False

Knowledge Check

6

APPLY: A confirm-pay page is frameable by any site. What failed?

Multiple choice

Knowledge Check

7

APPLY: True or False: Sending HSTS on a plain HTTP lab fully enables HSTS for browsers.

True or False

Knowledge Check

8

APPLY: curl http://192.168.0.1/ shows a TP-Link/Netgear “Router Admin” login. What do you do?

Multiple choice

Knowledge Check

9

APPLY: A teammate wants to Shodan open buckets “for A02 cloud.” What do you say?

Multiple choice

Knowledge Check

10

APPLY: You finish A02. What opens next, and what is Cyberlium legally?

Multiple choice

← Previous

Answer all 10 knowledge checks to continue. (0/10 answered)