Web › Module 7 › Lesson 5
Quiz — Authentication Failures
10 APPLY questions on A07 authn, sessions, and JWT verify.
Opening
A07 Authentication Failures — Module Quiz
Ten APPLY items on OWASP Top 10:2025 A07 as Cyberlium taught it: weak secrets/stuffing/MFA/reset; authn≠authz; session flags and server revoke; JWT verify≠decode, alg allowlist, exp; auth-hardening-lab.txt under $HOME/cyberlium-lab mode 600; teaching bind Course demo URL http://192.168.0.1/ is YOUR lab app — router admin login is OUT OF SCOPE (use SAFE). Hydra against strangers, BeEF, foreign JWT forge, LAN nmap, and pasted live secrets are failing answers. Original Cyberlium — not official OWASP certification. Next: A08 Unsigned Updates and CI Trust.
Knowledge Check
APPLY: Classmate opens hydra on campus SSO “for A07.” Response?
Multiple choice
Knowledge Check
APPLY: True or False: Login success means admin authorization is automatic.
True or False
Knowledge Check
APPLY: Best reset token design among these?
Multiple choice
Knowledge Check
APPLY: Logout clears UI only; server still accepts session id. Fix?
Multiple choice
Knowledge Check
APPLY: curl of http://192.168.0.1/ shows a TP-Link/Netgear/Huawei “Router Admin” login. What is in scope?
Multiple choice
Knowledge Check
APPLY: Decode-only JWT trust of role=admin. What is required?
Multiple choice
Knowledge Check
APPLY: True or False: Standard JWTs encrypt claims by default.
True or False
Knowledge Check
APPLY: Lab HOST changed to café IP for “realism.” Pass?
Multiple choice
Knowledge Check
APPLY: This path vs OWASP?
Multiple choice
Knowledge Check
APPLY: After A07 badge, what is next and still refused?
Multiple choice
Answer all 10 knowledge checks to continue. (0/10 answered)