SecurityMedium#81What is SQL injection, and how can it be prevented?SQL injection exploits vulnerabilities to execute malicious SQL. Prevent with parameterized queries, input validation, and least privilege access.
SecurityMedium#82Explain the concept of Cross-Site Scripting (XSS).XSS injects malicious scripts into web apps, executed by users' browsers. Prevent with input validation, output encoding, and CSP.
SecurityHard#83What is two-factor authentication (2FA)?2FA adds extra security by requiring two verification forms: something known (password) and something possessed (device).
SecurityMedium#84Describe the process of password hashing and salting.Hashing transforms passwords into hashes using algorithms; salting adds randomness, enhancing security against attacks.
SecurityMedium#85What is OAuth, and how does it work?OAuth allows third-party app access to user data without exposing credentials, using access tokens for authorization.
SecurityMedium#86How do you protect against session fixation attacks?Protect by regenerating session IDs post-authentication, using unpredictable IDs, and tying IDs to user authentication.
SecurityHard#87Explain the principles of least privilege and defense in depth.Least privilege limits access rights; defense in depth layers security. Both minimize attack surfaces and provide redundancy.
SecurityMedium#88What is a DDoS (Distributed Denial of Service) attack?A DDoS attack overwhelms a target with traffic, causing unavailability. Mitigate with DDoS protection, rate limiting, and traffic analysis.
SecurityMedium#89How can you secure sensitive data in a mobile app?Secure data by encrypting at rest and in transit, using secure authentication, and following best practices.
SecurityMedium#90Discuss the importance of security in API design.API security is vital to protect data and prevent unauthorized access, using authentication, validation, rate limiting, and encryption.