0
0
Nginxdevops~10 mins

HSTS header in Nginx - Interactive Code Practice

Choose your learning style9 modes available
Practice - 5 Tasks
Answer the questions below
1fill in blank
easy

Complete the code to add the HSTS header in nginx configuration.

Nginx
add_header Strict-Transport-Security "[1]";
Drag options to blanks, or click blank then click option'
Amax-age=31536000
Bmax-age=0
Cmax-age=100
Dmax-age=abc
Attempts:
3 left
💡 Hint
Common Mistakes
Using max-age=0 disables HSTS.
Using non-numeric values causes errors.
2fill in blank
medium

Complete the code to include subdomains in the HSTS policy.

Nginx
add_header Strict-Transport-Security "max-age=31536000; [1]";
Drag options to blanks, or click blank then click option'
Ainclude-subdomains
BincludeSubdomain
CincludeSubDomains
Dinclude_subdomains
Attempts:
3 left
💡 Hint
Common Mistakes
Misspelling the directive or using wrong case.
Using underscores or hyphens instead of camelCase.
3fill in blank
hard

Fix the error in the HSTS header to enable preload.

Nginx
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; [1]";
Drag options to blanks, or click blank then click option'
Apreload
Bpre-load
Cpre_load
Dpreload=true
Attempts:
3 left
💡 Hint
Common Mistakes
Adding '=' or other symbols after preload.
Using hyphens or underscores in the directive.
4fill in blank
hard

Fill both blanks to set HSTS with max age and include subdomains.

Nginx
add_header Strict-Transport-Security "[1]; [2]";
Drag options to blanks, or click blank then click option'
Amax-age=63072000
BincludeSubDomains
Cmax-age=31536000
DincludeSubdomain
Attempts:
3 left
💡 Hint
Common Mistakes
Using incorrect max-age values.
Misspelling includeSubDomains.
5fill in blank
hard

Fill all three blanks to set HSTS with max age, include subdomains, and preload.

Nginx
add_header Strict-Transport-Security "[1]; [2]; [3]";
Drag options to blanks, or click blank then click option'
Amax-age=15768000
BincludeSubDomains
Cpreload
Dmax-age=31536000
Attempts:
3 left
💡 Hint
Common Mistakes
Using too short max-age values.
Misspelling preload or includeSubDomains.