0% found this document useful (0 votes)
4 views2 pages

Model Question

The document outlines the model examination for the subject CCS374/Web Application Security scheduled for April 13, 2026. It includes three parts: Part A consists of 10 definitions and concepts related to web application security, Part B contains detailed questions on web architecture, vulnerabilities, SQL Injection, XSS, authentication, HTTPS, and input validation, and Part C focuses on end-to-end security practices or a comprehensive security diagram. The exam is structured to assess knowledge on various security threats and mitigation techniques in web applications.

Uploaded by

rsjegan1210
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views2 pages

Model Question

The document outlines the model examination for the subject CCS374/Web Application Security scheduled for April 13, 2026. It includes three parts: Part A consists of 10 definitions and concepts related to web application security, Part B contains detailed questions on web architecture, vulnerabilities, SQL Injection, XSS, authentication, HTTPS, and input validation, and Part C focuses on end-to-end security practices or a comprehensive security diagram. The exam is structured to assess knowledge on various security threats and mitigation techniques in web applications.

Uploaded by

rsjegan1210
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

MODEL EXAMINATION - 2026

Subject code/Name: CCS374/ Web Date: 13/04/2026


Application Security

Branch/Semester : CY/ IV Time: 01.00 PM to 04.00 PM([Link])

Academic Year : 2025-2026 Mark:100

PART-A (2*10=20)
1. Define Web Application Security.
2. What is a vulnerability in web applications?
3. Mention two common web application attacks.
4. 4Explain SQL Injection briefly.
5. Explain Cross-Site Scripting (XSS) briefly.
6. What is authentication?
7. What is session hijacking?
8. Define HTTPS.
9. Define encryption.
10. What is input validation?

PART-B (5*15=65)

11. a) Explain web application architecture and security threats.


OR
(b) Explain OWASP Top 10 vulnerabilities with examples.
12. a) Explain SQL Injection with a detailed example and prevention techniques.
OR
(b) Explain Cross-Site Scripting (XSS) with examples and prevention.
13. (a) Explain authentication and authorization mechanisms in detail.
OR
(b) Explain session management and session hijacking with examples.
14. (a) Explain HTTPS and SSL/TLS protocols in detail.
OR
(b) Explain encryption and decryption techniques used in web security.
15. (a) Explain input validation and output encoding techniques with examples.
OR
(b) Explain penetration testing and vulnerability scanning with step-by-step process.
PART-C (15*1=15)

16. (a) Explain end-to-end web application security practices covering:

 Vulnerabilities (SQLi, XSS, CSRF)


 Secure coding practices
 Input validation/output encoding
 Authentication & session management
 Security testing (penetration testing & vulnerability scanning)

OR
(b) Draw a comprehensive web application security diagram and explain mitigation for all major
attacks across all units.

Prepared by Verified by Approved by

You might also like