mediumMultiple Select
CAS-004 Practice Question: Which THREE of the following are common…
Which THREE of the following are common vulnerabilities found in web applications according to the OWASP Top 10 2021? (Select THREE.)
⚠ Common exam trap
A common trap is assuming SQL Injection remains a separate category in the OWASP Top 10 2021; however, it was merged into the broader Injection category (A03). Additionally, SSRF was added as a new category (A10), so it is a correct answer despite being a less familiar vulnerability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cryptographic Failures
The OWASP Top 10 2021 explicitly lists A. Cryptographic Failures (A02:2021) as a top web application risk, covering failures related to protecting data in transit and at rest, such as missing TLS, weak ciphers, or improper key management. B. Broken Access Control is ranked A01:2021, the most critical category, encompassing flaws like missing authorization checks, IDOR, and privilege escalation that let users act outside their intended permissions. C. Server-Side Request Forgery (SSRF) is A10:2021, a newly added category in the 2021 list, where an attacker induces the server to make requests to unintended internal or external resources. D. SQL Injection is not a standalone OWASP Top 10 2021 category; it falls under A03:2021 Injection, so it is not one of the three named items. E. Remote Code Execution via buffer overflow is a memory-safety issue more typical of native software and CWE listings, not a distinct OWASP Top 10 2021 web application category.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cryptographic Failures
Why this is correct
Cryptographic Failures ranks second in the OWASP Top 10 2021, covering exposure of sensitive data through weak encryption, poor key management or plaintext transmission. It satisfies the stem's requirement for a genuine 2021 category, having replaced the earlier Sensitive Data Exposure entry.
- ✓
Broken Access Control
Why this is correct
Broken Access Control holds the top position in the OWASP Top 10 2021, covering failures where enforcement of authenticated user permissions is missing, allowing attackers to act outside intended authorisation and access other users' data or functions.
- ✓
Server-Side Request Forgery (SSRF)
Why this is correct
Server-Side Request Forgery is a distinct OWASP Top 10 2021 category, where an application fetches a remote resource using a user-supplied URL without validating it, enabling access to internal systems. It satisfies the stem's requirement for a genuine 2021 vulnerability category.
- ✗
SQL Injection
Why it's wrong here
SQL Injection was folded into the broader A03:2021 Injection category in the OWASP Top 10 2021, so it is not listed as a standalone entry. It would be the right answer against the 2017 list, where it appeared as A1.
- ✗
Remote Code Execution (RCE) via buffer overflow
Why it's wrong here
Remote Code Execution via buffer overflow is not listed as a distinct category in the OWASP Top 10 2021. Although RCE may occur through injection, buffer overflow is not specifically addressed, so this is incorrect.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.