
CertNexusCyberSec First Responder (CFR)
Domain 1Objective 4
Objective 1.4 Exploit Web-Application Vulnerabilities. CYBERSEC-FIRST-RESPONDER Practice Questions (Page 3)
Part of the 1.0 Attack Computing Environments to Test Cybersecurity domain, which accounts for 52% of the CYBERSEC-FIRST-RESPONDER exam.
35questions here
7free pages
14concepts
52%of the exam
Questions 11–15
- 11
A web application uses only cookies to maintain session state and does not include anti-CSRF tokens. Which condition makes it vulnerable to CSRF?
Select an answer first - 12
After compromising a web server, an attacker uploads a PHP script that accepts commands via a URL parameter. What is this script called?
Select an answer first - 13
Which attack involves inserting malicious SQL code into a query to manipulate the database, such as bypassing authentication or extracting data?
Select an answer first - 14
An attacker submits the following to a search parameter: %3Cscript%3Ealert(1)%3C%2Fscript%3E. What is the purpose of this encoding?
Select an answer first - 15
A web application has a form that takes a user's name and includes it in a system command: system('echo ' . $_POST['name']);. A tester submits ; cat /etc/passwd as the name. The response includes the contents of the password file. Which vulnerability is being exploited?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CYBERSEC-FIRST-RESPONDER” is a trademark of its owner, used for identification only.