Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified DevNet Professional

Domain 4Objective 10

Implement Mitigation Strategies for OWASP Threats (such as XSS, CSRF, and SQL Injection) 350-901 Practice Questions (Page 2)

Part of the 4.0 Application Deployment and Security domain, which accounts for 20% of the 350-901 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
4concepts
20%of the exam

Questions 6–10

  1. 6expert · hard

    A DevNet engineer is reviewing a web application that has been in production for several years. The application has a login form, a search feature, and a profile update feature. A penetration test identified XSS, CSRF, and SQL injection vulnerabilities. The team has a limited budget and must fix the vulnerabilities in the next sprint. Which fix should the engineer prioritize?

    Select an answer first
  2. 7expert · hard

    A DevNet engineer is deploying a web application that uses a third-party single sign-on (SSO) service. The application sets a session cookie after successful authentication. The security team is concerned about CSRF on the logout endpoint. Which mitigation should the engineer implement?

    Select an answer first
  3. 8application · medium

    A DevNet engineer is developing a single-page application (SPA) that renders user-generated content. The application uses a JavaScript framework that automatically escapes data in templates. However, the engineer needs to render a rich text editor's HTML output. Which mitigation should the engineer implement to prevent XSS while allowing safe HTML?

    Select an answer first
  4. 9foundation · easy

    Which security concept involves layering multiple independent defenses so that if one control fails, another still provides protection?

    Select an answer first
  5. 10application · medium

    A DevNet engineer is reviewing a Python Flask application that queries a database. The current code builds SQL queries by concatenating user input directly into the query string. The team needs to fix this vulnerability without rewriting the entire data access layer. Which approach should the engineer recommend?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-901” is a trademark of its owner, used for identification only.