- Why is it critical to perform a penetration test on a web application and a web server prior to production implementation?
- What is a cross-site scripting attack? Explain in your own words. 3. What is a reflective cross-site scripting attack?
- If you can monitor when SQL injections are performed on an SQL database, what would you recommend as a security countermeasure to monitor your production SQL databases?
- Given that Apache and Internet Information Services (IIS) are the two most popular web application servers for Linux and Microsoft@ Windows platforms, what would you do to identify known software vulnerabilities and exploits?
- What can you do to ensure that your organization incorporates penetration testing and web application testing as part of its implementation procedures?
- What is the purpose of setting the DVWA security level to low before beginning the remaining lab steps?
Sample Solution