Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Associate Automation (CCNA Automation)

Domain 4Objective 10

10. Describe Top OWASP Threats (such as XSS, SQL Injections, and CSRF) 200-901 Practice Questions (Page 4)

Part of the 4.0 Application Deployment and Security domain, which accounts for 15% of the 200-901 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
5concepts
15%of the exam

Questions 16–20

  1. 16expert · hard

    A security engineer is reviewing a web application that has both XSS and CSRF vulnerabilities. The application uses cookies for authentication. The team wants to implement a single control that reduces the risk of both attacks. Which control is most effective for both?

    Select an answer first
  2. 17application · medium · select all that apply

    A development team is conducting a security review of a web application. They have identified the following issues: (1) user input is concatenated into SQL queries, (2) state-changing forms lack anti-CSRF tokens, and (3) user-supplied data is rendered without encoding. Which of the following are appropriate mitigations? Select all that apply.

    Select an answer first
  3. 18application · medium

    A user is logged into a banking website. In another browser tab, the user visits a malicious site that contains an image tag pointing to the banking site's transfer endpoint with parameters to move funds. The browser automatically sends the banking site's cookies with the request, and the transfer is executed. Which OWASP threat is this, and what is the most effective mitigation?

    Select an answer first
  4. 19foundation · easy

    A user is logged into a banking website. While browsing another site, the user clicks a link that triggers a request to the banking site to transfer funds to the attacker's account. The banking site does not verify the origin of the request. Which type of attack is this?

    Select an answer first
  5. 20application · medium

    A development team is hardening a web application that accepts user comments and later displays them, and also queries a database using the comment text. Which combination of controls provides the most comprehensive defense against both stored XSS and SQL injection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-901” is a trademark of its owner, used for identification only.