200-201 exam dumps

200-201 practice question 149 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 149

Single answer

A cybersecurity analyst is investigating a web application vulnerability affecting a company's customer portal. The attacker is able to inject malicious scripts into the application, which are then executed in the browser of anyone viewing the affected pages. Which type of web application attack is most likely occurring?

  1. A

    SQL Injection

  2. B

    Command Injection

  3. C

    Cross-Site Scripting (XSS)

  4. D

    Cross-Site Request Forgery (CSRF)

Show answer and explanation

Correct answer: C

Explanation

The attack described is consistent with Cross-Site Scripting (XSS), where malicious scripts are injected into a web application and executed in the browsers of affected users. This can lead to data theft, session hijacking, or other malicious activities. Other options, such as SQL Injection or Command Injection, target servers rather than user browsers, and CSRF involves tricking users into executing unintended actions, not injecting scripts.

  • A. Incorrect.

    SQL Injection involves inserting malicious SQL queries into input fields to manipulate a database. This does not match the attack described, as the issue involves executing malicious scripts in a user's browser.

  • B. Incorrect.

    Command Injection allows an attacker to execute arbitrary system commands on the server. This does not match the described scenario because the attack is targeting users' browsers, not the server.

  • C. Correct.

    Cross-Site Scripting (XSS) occurs when an attacker injects malicious scripts into a web application, which are then executed in the browser of users who access the affected pages. This matches the described attack scenario.

  • D. Incorrect.

    Cross-Site Request Forgery (CSRF) tricks a user into performing unwanted actions on a web application where they are authenticated. This does not involve the injection of malicious scripts into the application.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam