AI-Assisted Web Application Assessment
Final Quiz
Connecting to LMS...
Progress: in progress
Assessment
1. What is the proper role of AI in web application assessment?
A. Unsupervised exploitation
B. Advisory support for authorized analysis, documentation, and reasoning
C. Bypassing scope limits
D. Replacing human verification
2. Why must scope be defined before testing?
A. It guarantees no vulnerabilities exist
B. It replaces evidence collection
C. It lets AI ignore rules of engagement
D. It establishes what systems, accounts, actions, and time windows are authorized
3. How should AI-generated vulnerability suggestions be treated?
A. As hypotheses that require analyst verification
B. As confirmed findings
C. As automatic proof of compromise
D. As replacements for evidence
4. Which artifact may support web assessment evidence?
A. Unsupported guesses
B. Private data unrelated to scope
C. HTTP request and response records
D. Hidden assumptions
5. Why is human oversight required?
A. AI is always correct
B. AI can misunderstand context, hallucinate, or produce unsafe recommendations
C. Human review slows work without benefit
D. Oversight replaces authorization
6. What should a finding include?
A. Clear evidence, impact, severity reasoning, affected area, and remediation guidance
B. Only a vague label
C. Unsourced claims
D. Out-of-scope details
7. Why should sensitive data be minimized?
A. More sensitive data always improves results
B. Data handling does not matter during testing
C. Minimization replaces security controls
D. Assessment data may include credentials, tokens, customer data, or business information
8. What is a hallucination?
A. A verified vulnerability
B. A proxy setting
C. An AI output that is not supported by evidence or reliable context
D. A successful login
9. How can AI help with application mapping?
A. By organizing routes, roles, parameters, workflows, and notes for analyst review
B. By automatically approving all test activity
C. By ignoring scope
D. By deleting evidence
10. Why should scanner output be reviewed manually?
A. Scanner output is always perfect
B. Automated tools and AI summaries can produce false positives or miss context
C. Manual review is never useful
D. AI can confirm findings without evidence
11. How can AI support API review?
A. By bypassing authentication
B. By generating unauthorized requests
C. By hiding documentation
D. By summarizing endpoints, data flows, parameters, and authorization questions
12. What is a safe remediation recommendation?
A. A vague instruction to fix security
B. An unsupported accusation
C. A practical control improvement tied to the verified issue and application context
D. A suggestion to disable all logging
13. Why should answer positions be randomized in the quiz?
A. To avoid obvious answer patterns
B. To hide correct answers from the LMS
C. To remove the need for assessment quality
D. To make every question ambiguous
14. Which behavior is inappropriate?
A. Summarizing authorized evidence
B. Using AI to justify out-of-scope testing or unauthorized access
C. Drafting a report for analyst review
D. Organizing application notes
15. Which statement best summarizes AI-assisted web application assessment?
A. AI makes authorization unnecessary
B. AI replaces testing skill
C. AI output should be accepted without review
D. AI can improve authorized assessment workflows when scope, evidence, data protection, and human verification remain central
16. What should rules of engagement define?
A. Only the final report font
B. Permission for unlimited testing by default
C. Targets, windows, rate limits, data handling, communication paths, and escalation rules
D. A reason to skip evidence preservation
17. What is the safest way to use AI with code or API documentation?
A. Use it to summarize and generate review questions, then verify interpretations manually
B. Accept every interpretation as fact
C. Use it to bypass authentication
D. Ignore application context
18. What should happen before AI-drafted report language is delivered?
A. It should be published immediately
B. A qualified assessor should review it against verified evidence and scope
C. All evidence should be deleted
D. Severity should be chosen randomly
Submit Quiz
Previous