Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Associate Automation (CCNA Automation)

Domain 4Objective 10

10. Describe Top OWASP Threats (such as XSS, SQL Injections, and CSRF) 200-901 Practice Questions (Page 8)

Part of the 4.0 Application Deployment and Security domain, which accounts for 15% of the 200-901 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)

41questions here
9free pages
5concepts
15%of the exam

Questions 36–40

  1. 36application · medium

    A security auditor is categorizing vulnerabilities found in a web application: (1) a search page reflects user input without encoding, (2) a login form concatenates input into a SQL query, and (3) a device configuration form lacks anti-forgery protection. Which OWASP Top 10 categories should the auditor assign to these findings?

    Select an answer first
  2. 37application · medium

    A user is logged into a web application. The application uses cookies for session management but does not use CSRF tokens. An attacker creates a malicious page that submits a form to the application's 'change password' endpoint. The form is auto-submitted when the page loads. Which of the following is the most effective mitigation?

    Select an answer first
  3. 38expert · hard

    A network automation web app is being redesigned. The team must choose a security architecture that protects against XSS, SQL injection, and CSRF while minimizing performance overhead. Which approach best meets these requirements?

    Select an answer first
  4. 39expert · hard

    A security consultant is prioritizing remediation for a web application with limited budget. The app has: (1) reflected XSS in a search page, (2) SQL injection in a login form, (3) CSRF on a device configuration form, and (4) a missing Content-Security-Policy header. Which remediation should be prioritized first based on OWASP risk principles?

    Select an answer first
  5. 40application · medium

    An administrator is configuring a web application that allows users to change their email address. The application uses session cookies but does not include any anti-CSRF protection. Which additional control should be added to prevent CSRF attacks on this state-changing operation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-901” is a trademark of its owner, used for identification only.