Recall & Review
beginner
What is a bug bounty program?
A bug bounty program is an initiative where organizations invite security researchers to find and report software bugs, especially security vulnerabilities, in exchange for rewards or recognition.
Click to reveal answer
beginner
Why do companies run bug bounty programs?
Companies run bug bounty programs to improve their security by finding vulnerabilities before attackers do, saving money on fixing issues early, and building trust with users.
Click to reveal answer
beginner
Who can participate in bug bounty programs?
Anyone with security skills can participate, from professional security researchers to hobbyists, as long as they follow the program's rules and report bugs responsibly.
Click to reveal answer
intermediate
What types of bugs are usually rewarded in bug bounty programs?
Typically, security vulnerabilities like code injection, cross-site scripting, broken authentication, and data leaks are rewarded because they pose risks to users and systems.
Click to reveal answer
intermediate
What is responsible disclosure in bug bounty programs?
Responsible disclosure means reporting bugs privately to the company first, giving them time to fix the issue before making it public, to protect users from harm.
Click to reveal answer
What is the main goal of a bug bounty program?
✗ Incorrect
Bug bounty programs focus on finding security bugs early to protect systems and users.
Who usually receives rewards in bug bounty programs?
✗ Incorrect
Rewards go to those who find and report valid security issues.
What does responsible disclosure mean?
✗ Incorrect
Responsible disclosure protects users by allowing companies to fix bugs before public exposure.
Which of these is a common type of bug rewarded in bug bounty programs?
✗ Incorrect
Cross-site scripting is a security vulnerability often rewarded in bug bounty programs.
Why might a company prefer a bug bounty program over hiring only internal testers?
✗ Incorrect
Bug bounty programs leverage many external experts, increasing chances to find bugs.
Explain what a bug bounty program is and why it is important for cybersecurity.
Think about how companies use outside help to improve security.
You got /3 concepts.
Describe the concept of responsible disclosure and why it matters in bug bounty programs.
Consider the timing of sharing bug information.
You got /3 concepts.