Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 2Objective 6

2.6 Describe Web Application Attacks, Such as SQL Injection, Command Injections, and Cross-Site Scripting 200-201 Practice Questions (Page 6)

Part of the 2.0 Security Monitoring domain, which accounts for 25% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–2 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
3concepts
25%of the exam

Questions 26–29

  1. 26expert · hard

    A security analyst is reviewing a web application that has multiple vulnerabilities. The application has a file upload feature that passes the filename to a shell command, a search feature that is vulnerable to SQL injection, and a comment feature that is vulnerable to stored XSS. The analyst has limited time and resources. The application is used by a small team of internal users, not the public. Which vulnerability should be fixed first?

    Select an answer first
  2. 27application · medium

    A web application has a file upload feature that accepts a filename and passes it to a shell command to move the file. A security analyst discovers that uploading a file named `file.txt; rm -rf /` could delete files on the server. Which control is most effective to prevent this attack?

    Select an answer first
  3. 28application · medium

    A web developer at a retail company is reviewing a security report for the company's product search page. The report shows that a user submitted the following input in the search box: `' OR '1'='1`. The application returned all products in the database instead of only matching items. The developer wants to prevent this class of attack while still allowing legitimate search queries. Which remediation should the developer implement?

    Select an answer first
  4. 29application · medium

    A security analyst is reviewing a web application that allows users to look up account balances by entering an account number. The application constructs a SQL query by concatenating the user input. An attacker submits `1234 OR 1=1` and receives the balances of all accounts. Which of the following is the most effective mitigation to prevent this type of attack?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to 200-201

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.