Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Associate Automation (CCNA Automation)

Domain 4Objective 10

10. Describe Top OWASP Threats (such as XSS, SQL Injections, and CSRF) 200-901 Practice Questions (Page 3)

Part of the 4.0 Application Deployment and Security domain, which accounts for 15% of the 200-901 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
5concepts
15%of the exam

Questions 11–15

  1. 11application · medium

    A developer at a company is building a login form. The current code concatenates the username and password directly into a SQL query string. A security review flags this as vulnerable. Which remediation should the developer implement to prevent SQL injection?

    Select an answer first
  2. 12expert · hard

    A network monitoring portal has a legacy dashboard that renders device names in HTML without encoding. The development team wants to fix the XSS vulnerability but must preserve the ability to display device names that contain the ampersand character (&) as entered by users. The team is considering three options: (A) encode the device name with htmlspecialchars before rendering, (B) sanitize the device name by stripping all non-alphanumeric characters before storing it, (C) use a JavaScript-based client-side encoder. Which option best balances security and functional requirements?

    Select an answer first
  3. 13foundation · easy

    Which characteristic best describes DOM-based XSS?

    Select an answer first
  4. 14application · medium · select all that apply

    A development team is implementing a security checklist for a new network automation web app. Which three practices are effective mitigations for XSS, SQL injection, or CSRF? Select all that apply.

    Select an answer first
  5. 15expert · hard

    A developer is tasked with fixing a SQL injection vulnerability in a legacy application. The application uses dynamic SQL queries that are built from user input. The team cannot switch to an ORM or rewrite the data access layer. Which approach is the most secure under these constraints?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-901” is a trademark of its owner, used for identification only.