MODEL EXAMINATION - 2026
Subject code/Name: CCS374/ Web Date: 13/04/2026
Application Security
Branch/Semester : CY/ IV Time: 01.00 PM to 04.00 PM([Link])
Academic Year : 2025-2026 Mark:100
PART-A (2*10=20)
1. Define Web Application Security.
2. What is a vulnerability in web applications?
3. Mention two common web application attacks.
4. 4Explain SQL Injection briefly.
5. Explain Cross-Site Scripting (XSS) briefly.
6. What is authentication?
7. What is session hijacking?
8. Define HTTPS.
9. Define encryption.
10. What is input validation?
PART-B (5*15=65)
11. a) Explain web application architecture and security threats.
OR
(b) Explain OWASP Top 10 vulnerabilities with examples.
12. a) Explain SQL Injection with a detailed example and prevention techniques.
OR
(b) Explain Cross-Site Scripting (XSS) with examples and prevention.
13. (a) Explain authentication and authorization mechanisms in detail.
OR
(b) Explain session management and session hijacking with examples.
14. (a) Explain HTTPS and SSL/TLS protocols in detail.
OR
(b) Explain encryption and decryption techniques used in web security.
15. (a) Explain input validation and output encoding techniques with examples.
OR
(b) Explain penetration testing and vulnerability scanning with step-by-step process.
PART-C (15*1=15)
16. (a) Explain end-to-end web application security practices covering:
Vulnerabilities (SQLi, XSS, CSRF)
Secure coding practices
Input validation/output encoding
Authentication & session management
Security testing (penetration testing & vulnerability scanning)
OR
(b) Draw a comprehensive web application security diagram and explain mitigation for all major
attacks across all units.
Prepared by Verified by Approved by