Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CertNexus logo

CertNexusCyberSec First Responder (CFR)

Domain 1Objective 4

Objective 1.4 Exploit Web-Application Vulnerabilities. CYBERSEC-FIRST-RESPONDER Practice Questions (Page 4)

Part of the 1.0 Attack Computing Environments to Test Cybersecurity domain, which accounts for 52% of the CYBERSEC-FIRST-RESPONDER exam.

35questions here
7free pages
14concepts
52%of the exam

Questions 16–20

  1. 16application · medium

    A web application filters requests that contain '../' in the file parameter. A tester submits /download?file=%2e%2e%2f%2e%2e%2fetc%2fpasswd and successfully accesses the password file. Which technique is being used to bypass the filter?

    Select an answer first
  2. 17foundation · easy

    An attacker submits the following input to a search field: ; ls -la. The server executes the command and returns the directory listing. Which vulnerability is being exploited?

    Select an answer first
  3. 18foundation · easy

    A web form only validates input on the client side using JavaScript. Which weakness does this present?

    Select an answer first
  4. 19application · medium

    A web application allows users to download files by specifying a filename in the URL parameter: /download?file=report.pdf. A tester submits /download?file=../../../../etc/passwd and receives the contents of the password file. Which vulnerability is being exploited?

    Select an answer first
  5. 20foundation · easy

    Which vulnerability occurs when a web form does not properly validate user input, allowing an attacker to submit unexpected data types or values?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CYBERSEC-FIRST-RESPONDER” is a trademark of its owner, used for identification only.