Web › Module 9 › Lesson 5
Quiz — Logging and Alerting
10 APPLY questions on A09 must-log, alerts, and privacy.
Opening
A09 Security Logging and Alerting Failures — Module Quiz
Ten APPLY items on OWASP Top 10:2025 A09 as Cyberlium taught it: must-log security events; structured fields without secrets; alerts with owners/runbooks; fatigue policy; privacy never-log/redaction; logging-lab.txt under $HOME/cyberlium-lab mode 600; optional curl of http://192.168.0.1/ to generate a request you log locally. Router admin login at that IP is OUT OF SCOPE. Foreign SIEM scrapes, real PII gists, password logging, hydra, LAN nmap, and wiping others’ audit trails are failing answers. Original Cyberlium — not official OWASP certification. Next: A10 Fail-Open vs Fail-Closed.
Knowledge Check
APPLY: No failed-login or admin-change logs. A09?
Multiple choice
Knowledge Check
APPLY: True or False: Logging plaintext passwords helps MFA debugging in production.
True or False
Knowledge Check
APPLY: Logs exist; admin grants never page anyone. Gap?
Multiple choice
Knowledge Check
APPLY: Permanent disable of all alerts to reduce noise?
Multiple choice
Knowledge Check
APPLY: curl of http://192.168.0.1/ shows a TP-Link/Netgear/Huawei “Router Admin” login. What is in scope?
Multiple choice
Knowledge Check
APPLY: Framework logs Authorization headers. Action?
Multiple choice
Knowledge Check
APPLY: True or False: Fake sample lines are required instead of real customer data in the lab file.
True or False
Knowledge Check
APPLY: logging-lab.txt blank “we monitor.” Pass?
Multiple choice
Knowledge Check
APPLY: Path vs OWASP?
Multiple choice
Knowledge Check
APPLY: Next and still refused?
Multiple choice
Answer all 10 knowledge checks to continue. (0/10 answered)