Web › Module 6 › Lesson 5
Quiz — Insecure Design
10 APPLY questions on A06 design, logic, and local race literacy.
Opening
A06 Insecure Design — Module Quiz
Ten APPLY items on OWASP Top 10:2025 A06 Insecure Design as Cyberlium taught it: threat modeling lite (assets, actors, abuse cases, controls); business logic invariants and server-side recomputation; check-then-act races and limit overruns demonstrated only on a local HTTP counter YOU wrote at ; design-review-lab.txt under $HOME/cyberlium-lab mode 600. Course demo URL http://192.168.0.1/ is YOUR lab app — router admin login is OUT OF SCOPE (use SAFE). Bank-steal races, stranger checkout hunts, LAN nmap, hydra, and “WAF replaces business rules” are failing answers. Original Cyberlium teaching — not official OWASP certification. Next after this badge is A07 Authentication Failures: Broken Authentication Patterns.
Knowledge Check
APPLY: A team skips abuse cases because “we have a WAF.” What is A06 here?
Multiple choice
Knowledge Check
APPLY: True or False: Hiding admin UI controls is enough because users will not forge API fields.
True or False
Knowledge Check
APPLY: Client sends totalPrice in JSON for your loopback shop. Correct response?
Multiple choice
Knowledge Check
APPLY: Two parallel coupon applies both succeed once. Mechanism and in-scope lab?
Multiple choice
Knowledge Check
APPLY: curl of http://192.168.0.1/ shows a TP-Link/Netgear/Huawei “Router Admin” login. What is in scope?
Multiple choice
Knowledge Check
APPLY: True or False: Edge rate limits alone make one-time coupon races impossible.
True or False
Knowledge Check
APPLY: A finding on YOUR app should include which shape?
Multiple choice
Knowledge Check
APPLY: design-review-lab.txt is blank except “secured.” Pass or fail?
Multiple choice
Knowledge Check
APPLY: This path’s relationship to OWASP?
Multiple choice
Knowledge Check
APPLY: You finish A06. What opens next, and what stays refused?
Multiple choice
Answer all 10 knowledge checks to continue. (0/10 answered)