OSWE Offensive Security Web Expert Practice Test
OSWE Offensive Security Web Expert के लिए अपना आत्मविश्वास बढ़ाएँ। अवधारणाओं का अभ्यास करें, उत्तरों को समझें और हर सवाल के साथ अपना ज्ञान मज़बूत करें।
एक नमूना सवाल आज़माएँपरीक्षा का परिचय और विवरण
The Offensive Security Web Expert (OSWE) certification represents the pinnacle of web application security expertise, validating advanced offensive security skills through rigorous hands-on examination. This elite certification requires candidates to demonstrate sophisticated source code analysis, exploit development, and vulnerability chaining across complex, modern web applications. Unlike entry-level certifications, OSWE focuses on the methodology of discovering novel vulnerabilities in white-box scenarios, emphasizing the ability to read, understand, and weaponize application source code. Successful certification holders prove they can move beyond automated tools and standardized payloads to conduct professional-grade security assessments, identifying logic flaws, business process vulnerabilities, and complex multi-step attack chains that evade conventional testing. The certification is globally recognized as a benchmark for senior application security consultants, penetration testers, and red team operators, signifying a practitioner's ability to perform at an expert level in real-world engagements.
नमूना प्रश्न
अभ्यास कैसे काम करता है, यह जानने के लिए एक उत्तर चुनें और व्याख्या देखें।
An ASP.NET Web Forms (.NET Framework 4.8) application leaks `machineKey` from a misconfigured backup. What is the highest-impact exploitation primitive?
A Spring Boot 2.7 application uses Thymeleaf with `SpringStandardDialect` and renders a fragment via `model.addAttribute("greeting", request.getParameter("g"))` then ` `. The developer claims this is safe. Where (if anywhere) is the actual SSTI risk in a Spring/Thymeleaf application?
A code review of CareQueue's template preview feature focuses on sprint 17 code that recently moved from an admin-only route to an API endpoint. In the relevant path, a JWT verifier chooses the verification key from an untrusted header field before it checks issuer and audience. Which review finding should drive the authentication fix?
A code review of BeaconCMS's analytics preview feature focuses on sprint 16 code that recently moved from an admin-only route to an API endpoint. In the relevant path, a WebSocket handler passes a client-supplied container name into a shell command used to collect logs. Which change removes the command injection weakness?
Storing user passwords with which algorithm is recommended by OWASP ASVS / NIST 800-63B in 2024?