Application Attacks Quiz

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/8

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:57 PM on 9/14/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

9 Terms

1
New cards

What type of action allows an attacker to exploit the XSS vulnerability?

A) Code injection

B) Privilege escalation

C) Session hijacking

D) Packet sniffing

A)

Cross-site scripting (XSS) is a type of code injection that allows attackers to run malicious scripts in the context of a user's browser session.

2
New cards

Which of the following exploits targets a protocol used for managing and accessing networked resources?

A) CSRF/XSRF attack

B) XML injection attack

C) LDAP injection attack

D) SQL injection attack

C)

LDAP injection targets Lightweight Directory Access Protocol queries, allowing attackers to manipulate authentication or search parameters.

3
New cards

Which type of exploit targets web applications that generate content used to store and transport data?

A) SQL injection attack

B) CSRF/XSRF attack

C) XML injection attack

D) LDAP injection attack

C)

XML injection exploits improperly validated XML input to modify data, disrupt applications, or gain unauthorized access.

4
New cards

A type of exploit that relies on overwriting contents of memory to cause unpredictable results in an application is referred to as:

A) IV attack

B) Privilege escalation

C) Buffer overflow

D) DLL injection

C)

Buffer overflow attacks overrun memory boundaries, often allowing attackers to crash programs or execute malicious code.

5
New cards

A situation where an attacker intercepts and retransmits valid data exchange between an application and a server, or another application is known as:

A) Sideloading

B) Replay attack

C) Phishing attack

D) Race condition

B)

Replay attacks capture legitimate data transmissions and resend them to trick the system into granting unauthorized access.

6
New cards

Which of the following facilitate(s) privilege escalation attacks? (Select all that apply)

A) System/application vulnerabilities

B) Password hashing

C) System/application misconfigurations

D) Network segmentation

E) Social engineering techniques

A), C), E)

Privilege escalation is made possible through poor configurations, software vulnerabilities, and social engineering to bypass restrictions.

7
New cards

Which of the statements listed below apply to the CSRF/XSRF attack? (Select 3 answers)

A) Exploits the trust a website has in the user's web browser

B) A user is tricked by an attacker into submitting unauthorized web requests

C) Website executes attacker's requests

D) Exploits the trust a user's web browser has in a website

E) A malicious script is injected into a trusted website

F) User's browser executes attacker's script

A), B), C)

CSRF attacks trick users into unknowingly submitting requests to a site they are authenticated to, exploiting the site's trust in the user's session.

8
New cards

A dot-dot-slash attack is also referred to as:

A) Disassociation attack

B) On-path attack

C) Directory traversal attack

D) Downgrade attack

C)

Directory traversal (../) attacks allow access to files and directories outside the intended web server directory.

9
New cards

Which of the following URLs is a potential indicator of a directory traversal attack?

A) http://www.example.com/var/../etc/passwd

B) http://www.example.com/var/www/../../etc/passwd

C) http://www.example.com/var/www/files/../../../etc/passwd

D) http://www.example.com/var/www/files/images/../../../../etc/passwd

E) Any of the above

E)

All these URLs include patterns attempting to access restricted files outside the web root, indicating a potential directory traversal attack.