Courseiva
mediumMultiple Select

CAS-004 Practice Question: Which THREE of the following are common…

Which THREE of the following are common vulnerabilities found in web applications according to the OWASP Top 10 2021? (Select THREE.)

⚠ Common exam trap

A common trap is assuming SQL Injection remains a separate category in the OWASP Top 10 2021; however, it was merged into the broader Injection category (A03). Additionally, SSRF was added as a new category (A10), so it is a correct answer despite being a less familiar vulnerability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cryptographic Failures

The OWASP Top 10 2021 explicitly lists A. Cryptographic Failures (A02:2021) as a top web application risk, covering failures related to protecting data in transit and at rest, such as missing TLS, weak ciphers, or improper key management. B. Broken Access Control is ranked A01:2021, the most critical category, encompassing flaws like missing authorization checks, IDOR, and privilege escalation that let users act outside their intended permissions. C. Server-Side Request Forgery (SSRF) is A10:2021, a newly added category in the 2021 list, where an attacker induces the server to make requests to unintended internal or external resources. D. SQL Injection is not a standalone OWASP Top 10 2021 category; it falls under A03:2021 Injection, so it is not one of the three named items. E. Remote Code Execution via buffer overflow is a memory-safety issue more typical of native software and CWE listings, not a distinct OWASP Top 10 2021 web application category.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cryptographic Failures

    Why this is correct

    Cryptographic Failures ranks second in the OWASP Top 10 2021, covering exposure of sensitive data through weak encryption, poor key management or plaintext transmission. It satisfies the stem's requirement for a genuine 2021 category, having replaced the earlier Sensitive Data Exposure entry.

  • ✓

    Broken Access Control

    Why this is correct

    Broken Access Control holds the top position in the OWASP Top 10 2021, covering failures where enforcement of authenticated user permissions is missing, allowing attackers to act outside intended authorisation and access other users' data or functions.

  • ✓

    Server-Side Request Forgery (SSRF)

    Why this is correct

    Server-Side Request Forgery is a distinct OWASP Top 10 2021 category, where an application fetches a remote resource using a user-supplied URL without validating it, enabling access to internal systems. It satisfies the stem's requirement for a genuine 2021 vulnerability category.

  • ✗

    SQL Injection

    Why it's wrong here

    SQL Injection was folded into the broader A03:2021 Injection category in the OWASP Top 10 2021, so it is not listed as a standalone entry. It would be the right answer against the 2017 list, where it appeared as A1.

  • ✗

    Remote Code Execution (RCE) via buffer overflow

    Why it's wrong here

    Remote Code Execution via buffer overflow is not listed as a distinct category in the OWASP Top 10 2021. Although RCE may occur through injection, buffer overflow is not specifically addressed, so this is incorrect.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.