1/8
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What type of action allows an attacker to exploit the XSS vulnerability?
A) Code injection
B) Privilege escalation
C) Session hijacking
D) Packet sniffing
A)
Cross-site scripting (XSS) is a type of code injection that allows attackers to run malicious scripts in the context of a user's browser session.
Which of the following exploits targets a protocol used for managing and accessing networked resources?
A) CSRF/XSRF attack
B) XML injection attack
C) LDAP injection attack
D) SQL injection attack
C)
LDAP injection targets Lightweight Directory Access Protocol queries, allowing attackers to manipulate authentication or search parameters.
Which type of exploit targets web applications that generate content used to store and transport data?
A) SQL injection attack
B) CSRF/XSRF attack
C) XML injection attack
D) LDAP injection attack
C)
XML injection exploits improperly validated XML input to modify data, disrupt applications, or gain unauthorized access.
A type of exploit that relies on overwriting contents of memory to cause unpredictable results in an application is referred to as:
A) IV attack
B) Privilege escalation
C) Buffer overflow
D) DLL injection
C)
Buffer overflow attacks overrun memory boundaries, often allowing attackers to crash programs or execute malicious code.
A situation where an attacker intercepts and retransmits valid data exchange between an application and a server, or another application is known as:
A) Sideloading
B) Replay attack
C) Phishing attack
D) Race condition
B)
Replay attacks capture legitimate data transmissions and resend them to trick the system into granting unauthorized access.
Which of the following facilitate(s) privilege escalation attacks? (Select all that apply)
A) System/application vulnerabilities
B) Password hashing
C) System/application misconfigurations
D) Network segmentation
E) Social engineering techniques
A), C), E)
Privilege escalation is made possible through poor configurations, software vulnerabilities, and social engineering to bypass restrictions.
Which of the statements listed below apply to the CSRF/XSRF attack? (Select 3 answers)
A) Exploits the trust a website has in the user's web browser
B) A user is tricked by an attacker into submitting unauthorized web requests
C) Website executes attacker's requests
D) Exploits the trust a user's web browser has in a website
E) A malicious script is injected into a trusted website
F) User's browser executes attacker's script
A), B), C)
CSRF attacks trick users into unknowingly submitting requests to a site they are authenticated to, exploiting the site's trust in the user's session.
A dot-dot-slash attack is also referred to as:
A) Disassociation attack
B) On-path attack
C) Directory traversal attack
D) Downgrade attack
C)
Directory traversal (../) attacks allow access to files and directories outside the intended web server directory.
Which of the following URLs is a potential indicator of a directory traversal attack?
A) http://www.example.com/var/../etc/passwd
B) http://www.example.com/var/www/../../etc/passwd
C) http://www.example.com/var/www/files/../../../etc/passwd
D) http://www.example.com/var/www/files/images/../../../../etc/passwd
E) Any of the above
E)
All these URLs include patterns attempting to access restricted files outside the web root, indicating a potential directory traversal attack.