100-160 exam dumps

100-160 practice question 205 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 205

Select 3

An organization has discovered a vulnerability in one of its web applications that could allow attackers to execute SQL injection attacks. The application is used to process sensitive customer data, and a successful attack could lead to data theft. Based on this scenario, which of the following statements reflects the correct approach to managing this risk?

  1. A

    Apply input validation and parameterized queries to mitigate the vulnerability.

  2. B

    Accept the risk, as the likelihood of exploitation is extremely low.

  3. C

    Determine the level of risk by assessing the likelihood of exploitation and the potential impact.

  4. D

    Disregard the vulnerability since no attacks have been reported so far.

  5. E

    Implement a web application firewall (WAF) to reduce the likelihood of exploitation.

Show answer and explanation

Correct answers: A, C, E

Explanation

Effective risk management involves identifying vulnerabilities, assessing the associated risks (likelihood and impact), and implementing appropriate mitigation strategies. In this scenario, applying input validation and parameterized queries directly addresses the vulnerability, while a WAF provides an additional layer of protection. Assessing the risk level ensures that the organization can prioritize and respond appropriately. Accepting or ignoring the risk without proper evaluation is not a recommended cybersecurity practice.

  • A. Correct.

    Applying input validation and parameterized queries is a direct mitigation strategy to address SQL injection vulnerabilities. This reduces the likelihood of exploitation.

  • B. Incorrect.

    Accepting the risk without further analysis is not a recommended approach, as the potential impact (data theft) is significant, and the likelihood of exploitation must first be properly assessed.

  • C. Correct.

    Determining the level of risk by analyzing the likelihood and impact is a critical step in risk management. It helps prioritize the vulnerability and decide on appropriate actions.

  • D. Incorrect.

    Disregarding the vulnerability is not a responsible approach to cybersecurity, particularly for a vulnerability that could lead to significant data theft.

  • E. Correct.

    Implementing a web application firewall (WAF) can help reduce the likelihood of exploitation by blocking malicious traffic targeting the vulnerability.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam