Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Associate Automation (CCNA Automation)

Domain 4Objective 10

10. Describe Top OWASP Threats (such as XSS, SQL Injections, and CSRF) 200-901 Practice Questions (Page 5)

Part of the 4.0 Application Deployment and Security domain, which accounts for 15% of the 200-901 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
5concepts
15%of the exam

Questions 21–25

  1. 21foundation · easy

    Which of the following is a category that appears in the OWASP Top 10 list?

    Select an answer first
  2. 22application · medium

    An administrator of a network management web app notices that authenticated users are changing their own device passwords through a URL like /changePassword?new=attacker. The change request is sent as a GET request and the app relies only on the session cookie for authentication. Which additional control should be implemented to prevent an attacker from forcing a password change?

    Select an answer first
  3. 23application · medium

    A security analyst is investigating an incident where a user's session was hijacked. The user had visited a forum that allowed HTML in posts. The attacker's post contained a script that sent the user's cookies to an external server. Which OWASP threat category does this attack belong to, and what is the primary mitigation?

    Select an answer first
  4. 24application · medium

    A network automation portal accepts a device name in a search field and builds a query like SELECT * FROM devices WHERE name = '” + userInput + “'. A user enters 'dev1' OR '1'='1' and receives the full device table. Which remediation should the developer implement?

    Select an answer first
  5. 25foundation · easy

    A developer is reviewing a web application that displays user comments on a public page. An attacker submits a comment containing JavaScript that executes in the browsers of other users when they view the page. Which type of XSS attack is this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-901” is a trademark of its owner, used for identification only.