
CertNexusCyberSec First Responder (CFR)
Domain 3Objective 3
Objective 3.3 Protect Software. CYBERSEC-FIRST-RESPONDER Practice Questions (Page 4)
Part of the 3.0 Address the Security Concerns of Computing Environments domain, which accounts for 28% of the CYBERSEC-FIRST-RESPONDER exam.
53questions here
11free pages
18concepts
28%of the exam
Questions 16–20
- 16
Which file extension should be blocked in a typical web application upload?
Select an answer first - 17
Why is scrubbing metadata from uploaded files important?
Select an answer first - 18
What is the primary purpose of applying security patches to software?
Select an answer first - 19
A web application uses anti-CSRF tokens to protect forms. The tokens are generated per session and stored in the user's session. An attacker discovers that the token is not being rotated after login, and the same token is used for the entire session. What is the primary security risk of this implementation?
Select an answer first - 20
A development team is building a search feature that queries a database. The team wants to prevent SQL injection while allowing users to search for partial matches (e.g., 'prod%' for products starting with 'prod'). Which combination of techniques should be used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CYBERSEC-FIRST-RESPONDER” is a trademark of its owner, used for identification only.