Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Security

Domain 1Objective 2

1.2 Describe Security Vulnerabilities and Exploits Such as Software Bugs, Weak And/or Hardcoded Passwords, OWASP Top Ten, Missing Encryption Ciphers, Buffer Overflow, Path Traversal, Cross-Site Scripting/forgery, SQL Injection, and Identification and Prioritization Using CVEs and CVSS Scores 350-701 Practice Questions (Page 7)

Part of the Security Concepts domain, which accounts for 20% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–2 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
10concepts
20%of the exam

Questions 31–35

  1. 31foundation · easy

    What is the primary impact of a successful SQL injection attack?

    Select an answer first
  2. 32application · medium

    A security analyst is investigating a report that a user's session cookie was stolen after visiting a malicious website. The malicious website displayed a comment that contained a script that sent the cookie to an attacker's server. Which type of XSS attack is this, and what is the primary defense?

    Select an answer first
  3. 33foundation · easy

    What is the purpose of a CVE identifier?

    Select an answer first
  4. 34application · medium

    A penetration tester is assessing a web application and finds that user-supplied data is reflected in the response without proper encoding, allowing an attacker to inject scripts. The tester also finds that the application is vulnerable to SQL injection. According to the OWASP Top Ten, which two categories do these findings belong to?

    Select an answer first
  5. 35application · medium

    A security analyst is reviewing a vulnerability scan report for a web application. The report lists a critical SQL injection vulnerability with a CVSS v3.1 base score of 9.8, and a moderate XSS vulnerability with a score of 6.1. The organization has limited patching resources and must prioritize remediation. Which action should the analyst take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.