Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Associate Automation (CCNA Automation)

Domain 4Objective 10

10. Describe Top OWASP Threats (such as XSS, SQL Injections, and CSRF) 200-901 Practice Questions (Page 2)

Part of the 4.0 Application Deployment and Security domain, which accounts for 15% of the 200-901 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
5concepts
15%of the exam

Questions 6–10

  1. 6application · medium

    A security auditor is reviewing a web application and finds that the application exposes detailed error messages that reveal SQL query structure. The auditor also finds that user-supplied data is reflected in error pages without encoding. Which OWASP Top 10 categories are most directly relevant to these findings?

    Select an answer first
  2. 7application · medium

    A web application uses a JavaScript framework that reads a URL parameter and directly sets innerHTML on a page element. An attacker crafts a link that causes the browser to execute a script. Which type of XSS is this, and which mitigation is most effective?

    Select an answer first
  3. 8application · medium

    A network engineer is reviewing a web application that displays user-supplied search terms in the page without any encoding. An attacker crafts a URL with a malicious script in the search parameter, and when a victim clicks the link, the script executes in the victim's browser. Which OWASP threat is being exploited, and which mitigation would directly prevent this specific attack?

    Select an answer first
  4. 9foundation · easy

    Which statement accurately describes how SQL injection attacks manipulate database queries?

    Select an answer first
  5. 10expert · hard

    A web application uses a single-page application (SPA) architecture. The SPA makes API calls to a backend that uses cookie-based authentication. The team wants to protect against CSRF. The API is accessed from multiple subdomains. Which CSRF defense is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-901” is a trademark of its owner, used for identification only.