
CertNexusCyberSec First Responder (CFR)
Domain 1Objective 4
Objective 1.4 Exploit Web-Application Vulnerabilities. CYBERSEC-FIRST-RESPONDER Practice Questions (Page 6)
Part of the 1.0 Attack Computing Environments to Test Cybersecurity domain, which accounts for 52% of the CYBERSEC-FIRST-RESPONDER exam.
35questions here
7free pages
14concepts
52%of the exam
Questions 26–30
- 26
A penetration tester is assessing a customer portal that uses a login form. The application filters single quotes but does not filter double quotes or backslashes. The tester submits the following as the username: admin" OR "1"="1. The login succeeds without a valid password. Which vulnerability did the tester exploit?
Select an answer first - 27
A web application allows users to upload profile pictures. The application checks the file extension but does not check the file content. A tester uploads a file named avatar.php.jpg that contains PHP code. The file is stored in the web root and can be accessed directly. Which vulnerability is being exploited?
Select an answer first - 28
A web application filters requests that contain '../' in the file parameter. The filter is case-sensitive and does not decode URL encoding. A tester wants to access a file outside the web root. Which payload would bypass the filter?
Select an answer first - 29
Which attack exploits insufficient sanitization of file path parameters to access files outside the web root, such as /etc/passwd?
Select an answer first - 30
A penetration tester successfully uploads a PHP file to a web server. The file contains code that executes commands passed via a query parameter. The tester accesses the file and runs whoami. Which vulnerability is being exploited?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CYBERSEC-FIRST-RESPONDER” is a trademark of its owner, used for identification only.