Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 6

2.6 Describe Web Application Attacks, Such as SQL Injection, Command Injections, and Cross-Site Scripting 200-201 Practice Questions (Page 1)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
3concepts
25%of the exam

Questions 1–5

  1. 1foundation · easy

    Which of the following best describes how cross-site scripting (XSS) attacks work?

    Select an answer first
  2. 2application · medium

    A security analyst is reviewing a web application that allows users to search for products by name. The application constructs a SQL query by concatenating the user input. An attacker submits `product' UNION SELECT username, password FROM users--` and receives a list of usernames and password hashes in the response. Which of the following best describes the attack and the most effective mitigation?

    Select an answer first
  3. 3application · medium

    A security analyst is examining web server logs and finds a request to a login page with the parameter `username=admin'--`. The application returned a successful login response without a valid password. Which attack is most likely being attempted?

    Select an answer first
  4. 4application · medium

    A security analyst is investigating a phishing email that contains a link to a legitimate website. The link includes a parameter that reflects the user's input in the page without proper sanitization. When a victim clicks the link, a script executes in their browser and sends their session cookie to an attacker-controlled server. Which attack is this?

    Select an answer first
  5. 5application · medium

    A security analyst is reviewing a web application's login form. The application constructs a SQL query by concatenating the username and password directly into the query string. An attacker submits `' OR '1'='1` as the username and a random password. Which outcome is most likely?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.