Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Security

Domain 1Objective 2

1.2 Describe Security Vulnerabilities and Exploits Such as Software Bugs, Weak And/or Hardcoded Passwords, OWASP Top Ten, Missing Encryption Ciphers, Buffer Overflow, Path Traversal, Cross-Site Scripting/forgery, SQL Injection, and Identification and Prioritization Using CVEs and CVSS Scores 350-701 Practice Questions (Page 6)

Part of the Security Concepts domain, which accounts for 20% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
10concepts
20%of the exam

Questions 26–30

  1. 26foundation · easy

    What is the typical result of a buffer overflow that allows an attacker to execute arbitrary code?

    Select an answer first
  2. 27application · medium

    A web application allows users to download files by specifying a filename in the URL, such as /download?file=report.pdf. An attacker discovers that by using ../etc/passwd, they can retrieve the system's password file. Which vulnerability is being exploited, and what is the most effective mitigation?

    Select an answer first
  3. 28expert · medium

    A web application allows users to upload and download files. The application stores files in a directory and uses the filename provided by the user to retrieve them. An attacker discovers that by using encoded traversal sequences like %2e%2e%2f, they can access files outside the intended directory. The application currently only filters for '../'. Which action should be taken to effectively mitigate this vulnerability?

    Select an answer first
  4. 29foundation · easy

    Which of the following is an example of a weak encryption cipher that should be avoided?

    Select an answer first
  5. 30foundation · easy

    Which coding practice is most effective in preventing SQL injection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.