0. OWASP Flashcards
What does OWASP stand for?
Open Web Application Security Project
True or False: OWASP is a non-profit organization.
True
Fill in the blank: OWASP provides resources for improving the security of _______.
software
What is the primary focus of OWASP?
To improve the security of software.
What is the OWASP Top Ten?
A list of the ten most critical web application security risks.
Which of the following is one of the OWASP Top Ten risks? (A) SQL Injection (B) Buffer Overflow (C) Cross-Site Scripting (D) Both A and C
D
True or False: OWASP provides tools and documentation for developers.
True
What year was OWASP founded?
2001
Name one project that OWASP offers.
OWASP ZAP (Zed Attack Proxy)
What kind of community does OWASP foster?
An open community that encourages collaboration.
Fill in the blank: OWASP is known for its _______ resources.
educational
What is the purpose of the OWASP Foundation?
To support the OWASP community and its projects.
True or False: OWASP only focuses on web applications.
False
What is a key principle of OWASP’s approach to security?
Security by design.
What type of content does OWASP publish?
Guides, tools, and standards related to application security.
Which OWASP project is designed for testing web applications?
OWASP Web Security Testing Guide
True or False: OWASP provides a certification program for security professionals.
False
What is the role of OWASP chapters?
To provide local community support and events.
Fill in the blank: OWASP’s mission is to make software security visible so that individuals and organizations can make informed decisions.
visible
Which OWASP project provides a framework for secure coding practices?
OWASP Secure Coding Practices
What is the OWASP Application Security Verification Standard (ASVS)?
A framework of security requirements for designing, developing, and testing secure applications.
True or False: OWASP resources are only available in English.
False
What does OWASP encourage among software developers?
To integrate security into their development lifecycle.
How often is the OWASP Top Ten list updated?
Every few years.
What is the OWASP Cheat Sheet Series?
A collection of concise good practice guides for application developers.
Fill in the blank: OWASP is funded by _______ and donations.
sponsorships
What is one of the goals of OWASP?
To educate and promote security awareness.