How do you set a response header to indicate the content should be downloaded as a file?

  • response.setHeader("Content-Disposition", "attachment; filename=example.txt");
  • response.setHeader("Content-Encoding", "gzip");
  • response.setHeader("Content-Transfer-Encoding", "binary");
  • response.setHeader("Content-Type", "application/octet-stream");
To indicate that the content should be downloaded as a file, you can use the response.setHeader("Content-Disposition", "attachment; filename=example.txt"); method.

In the context of XSS prevention, what does the acronym CSP stand for?

  • Content-Security-Policy
  • Content-Security-Protocol
  • Cookie-Security-Protocol
  • Cross-Site Policy
In the context of XSS prevention, CSP stands for Content-Security-Policy. It is a security header that helps prevent XSS attacks by specifying which content can be executed on a web page.

Which JavaScript framework automatically escapes output to prevent XSS attacks?

  • AngularJS
  • React
  • Vue.js
  • jQuery
AngularJS automatically escapes output to prevent XSS attacks by default, helping developers build more secure web applications.

How does a Content Security Policy (CSP) help in preventing XSS attacks?

  • It allows only inline scripts
  • It encrypts the communication
  • It filters HTTP headers
  • It restricts the sources of content
A Content Security Policy (CSP) helps prevent XSS attacks by restricting the sources of content, reducing the risk of malicious script execution from unauthorized sources.

To maintain a separation of concerns, servlets in MVC should not directly manipulate the __________.

  • Controller
  • Database
  • Model
  • View
To maintain a separation of concerns, servlets in MVC should not directly manipulate the Controller.

The __________ method in servlets is often used to dispatch requests to different handlers in an MVC framework.

  • doDispatch()
  • doPost()
  • init()
  • service()
The doDispatch() method in servlets is often used to dispatch requests to different handlers in an MVC framework.

In a complex web application using MVC and servlets, a new feature requires integration of a third-party service. Where should this integration primarily take place?

  • In a separate utility class
  • In the Controller
  • In the Model
  • In the View
In MVC architecture, business logic, including third-party service integration, is primarily handled in the Controller. This ensures separation of concerns and makes the application more modular.

What is the significance of using HttpOnly cookies in the context of XSS prevention?

  • They are encrypted during transmission
  • They can only be accessed via HTTP
  • They cannot be accessed by JavaScript
  • They have a longer expiration time
HttpOnly cookies cannot be accessed by JavaScript, making them more secure against XSS attacks as malicious scripts won't have access to sensitive cookie information.

What is the key difference between Stored XSS and Reflected XSS attacks?

  • Reflected XSS involves non-persistent injection
  • Reflected XSS targets the client-side
  • Stored XSS involves persistent injection
  • Stored XSS targets the server-side
Stored XSS involves the injection of malicious scripts that persist on the target, whereas Reflected XSS involves non-persistent injection and reflects the payload back to the user.

How can input sanitization be ineffective against certain advanced XSS attacks?

  • By encoding payloads
  • By exploiting browser vulnerabilities
  • By using Content Security Policy (CSP)
  • By using client-side validation
Advanced XSS attacks may bypass input sanitization through techniques like exploiting browser vulnerabilities, making sanitization ineffective in preventing such attacks.