
CertNexusCyberSec First Responder (CFR)
Domain 1Objective 4
Objective 1.4 Exploit Web-Application Vulnerabilities. CYBERSEC-FIRST-RESPONDER Practice Questions (Page 4)
Part of the 1.0 Attack Computing Environments to Test Cybersecurity domain, which accounts for 52% of the CYBERSEC-FIRST-RESPONDER exam.
35questions here
7free pages
14concepts
52%of the exam
Questions 16–20
- 16
A web application filters requests that contain '../' in the file parameter. A tester submits /download?file=%2e%2e%2f%2e%2e%2fetc%2fpasswd and successfully accesses the password file. Which technique is being used to bypass the filter?
Select an answer first - 17
An attacker submits the following input to a search field: ; ls -la. The server executes the command and returns the directory listing. Which vulnerability is being exploited?
Select an answer first - 18
A web form only validates input on the client side using JavaScript. Which weakness does this present?
Select an answer first - 19
A web application allows users to download files by specifying a filename in the URL parameter: /download?file=report.pdf. A tester submits /download?file=../../../../etc/passwd and receives the contents of the password file. Which vulnerability is being exploited?
Select an answer first - 20
Which vulnerability occurs when a web form does not properly validate user input, allowing an attacker to submit unexpected data types or values?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CYBERSEC-FIRST-RESPONDER” is a trademark of its owner, used for identification only.