Your question is Test Internal Web App Security. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
A newly developed internal web application is about to be rolled out to employees, and you want confidence that it does not have obvious, preventable security weaknesses before adoption expands.
How would you test a newly developed internal web application for common security flaws?