Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified DevNet Professional

Domain 4Objective 10

Implement Mitigation Strategies for OWASP Threats (such as XSS, CSRF, and SQL Injection) 350-901 Practice Questions (Page 4)

Part of the 4.0 Application Deployment and Security domain, which accounts for 20% of the 350-901 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
4concepts
20%of the exam

Questions 16–20

  1. 16application · medium

    A DevNet engineer is deploying a web application that handles sensitive user data. The security team requires a defense-in-depth approach to mitigate OWASP threats. The engineer has already implemented input validation and output encoding. Which additional security header should the engineer configure to provide an extra layer of protection against XSS and data injection?

    Select an answer first
  2. 17foundation · easy

    Which of the following is a standard server-side control used to verify that a submitted form request originated from the application's own web page, not from a malicious third-party site?

    Select an answer first
  3. 18application · medium

    A DevNet engineer is configuring a web application that uses cookies for session management. The application is served over HTTPS. The security team wants to reduce the risk of CSRF attacks. Which cookie attribute should the engineer set to provide the most effective protection against cross-site request forgery?

    Select an answer first
  4. 19application · medium

    A DevNet engineer is building a web application that renders user-generated comments. The team has already implemented input validation to reject obvious script tags. However, a security review flags that users can still inject event handlers like onmouseover into HTML attributes. Which additional mitigation should the engineer implement to address this remaining XSS risk?

    Select an answer first
  5. 20foundation · easy

    Which security header, when properly configured, instructs the browser to only load and execute scripts from approved sources, thereby reducing the impact of cross-site scripting (XSS) vulnerabilities?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to 350-901

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-901” is a trademark of its owner, used for identification only.