Slide 27 of 28
Part 4 · QuizSlide 27
Slide 27 · Quiz
Five questions. No pressure.
Test what you understood — not what you memorized.
QUESTION 01 OF 05
In the 2012 GitHub breach, Egor Homakov added public_key[user_id]=4223 to his HTTP request. What made this exploit possible?
QUESTION 02 OF 05
What was wrong with Peloton's "private account" feature before it was fixed?
QUESTION 03 OF 05
A developer adds a "resetToken" field to the user database model and the user serializer returns all model fields by default. What's the risk?
QUESTION 04 OF 05
Why is an allowlist safer than a blocklist for protecting against mass assignment?
QUESTION 05 OF 05
In the OWASP dating app scenario, a user can get another user's fullName and recentLocation by using the "report user" feature. What type of failure is this?
← Back Done → See what you learned