
CertNexusCyberSec First Responder (CFR)
Domain 1Objective 4
Objective 1.4 Exploit Web-Application Vulnerabilities. CYBERSEC-FIRST-RESPONDER Practice Questions (Page 7)
Part of the 1.0 Attack Computing Environments to Test Cybersecurity domain, which accounts for 52% of the CYBERSEC-FIRST-RESPONDER exam.
35questions here
7free pages
14concepts
52%of the exam
Questions 31–35
- 31
A web application has a search form that takes a user input and displays it in the page without sanitization. A tester submits <script>alert(1)</script> in the search field. The script executes in the tester's browser. Which vulnerability is being exploited?
Select an answer first - 32
Which vulnerability allows an attacker to make the web server send crafted requests to internal resources, such as cloud metadata endpoints or internal services?
Select an answer first - 33
An application includes files using a parameter like ?page=about.php. An attacker changes it to ?page=../../../../etc/passwd. Which vulnerability is being exploited?
Select an answer first - 34
Which tool is commonly used to intercept and analyze HTTP traffic between a browser and a web application, allowing testers to view and modify requests?
Select an answer first - 35
Which attack forces an authenticated user's browser to send a forged HTTP request to a vulnerable web application, performing an action the user did not intend?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CYBERSEC-FIRST-RESPONDER
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CYBERSEC-FIRST-RESPONDER” is a trademark of its owner, used for identification only.