into a page, what happens?","url":"https://courseiva.com/questions/giac/giac-gcih/refer-to-the-exhibit-if-an-attacker-successfully-injects-s-imgc3"},{"@type":"ListItem","position":22,"name":"An incident handler is analyzing a web application that uses a NoSQL database. The application constructs queries by dir…","url":"https://courseiva.com/questions/giac/giac-gcih/an-incident-handler-is-analyzing-a-web-application-that-uses-jeche"},{"@type":"ListItem","position":23,"name":"A GCIH analyst is investigating a web application that uses Java deserialization to process user-supplied session object…","url":"https://courseiva.com/questions/giac/giac-gcih/a-gcih-analyst-is-investigating-a-web-application-that-uses--9st79"},{"@type":"ListItem","position":24,"name":"When evaluating potential SQL injection in an application, what is the most significant indicator that an application is…","url":"https://courseiva.com/questions/giac/giac-gcih/when-evaluating-potential-sql-injection-in-an-application-w-kc7sv"},{"@type":"ListItem","position":25,"name":"An incident handler is investigating a web application that allows users to upload profile pictures. The application sto…","url":"https://courseiva.com/questions/giac/giac-gcih/an-incident-handler-is-investigating-a-web-application-that--ui9a3"},{"@type":"ListItem","position":26,"name":"An incident responder investigates a web application breach where an attacker successfully extracted sensitive user data…","url":"https://courseiva.com/questions/giac/giac-gcih/an-incident-responder-investigates-a-web-application-breach-zond0"},{"@type":"ListItem","position":27,"name":"Which of the following describes the primary danger of an Insecure Deserialization vulnerability in a web application?","url":"https://courseiva.com/questions/giac/giac-gcih/which-of-the-following-describes-the-primary-danger-of-an-in-x11b2"},{"@type":"ListItem","position":28,"name":"During a web application penetration test, an assessor discovers an endpoint vulnerable to OS Command Injection via an i…","url":"https://courseiva.com/questions/giac/giac-gcih/during-a-web-application-penetration-test-an-assessor-disco-p7w0w"}]}
CCNA Web App Injection Attacks Questions
28 questions · Web App Injection Attacks · All types, answers revealed
An incident handler is analyzing an incident where a web application was compromised via SQL injection. The backend database uses a modern relational database management system. Which TWO of the following remediation strategies are considered primary defenses against SQL injection attacks? (Choose TWO)
Select 2 answers
A.Implementing parameterized queries or prepared statements for all database interactions
B.Enabling client-side JavaScript validation to strip out single quotes and semicolons
C.Applying robust input validation and whitelisting against expected parameter formats
D.Relying exclusively on Web Application Firewall signature blocking rules
E.Encoding all database query outputs using HTML entity encoding before rendering
AnswersA, C
Parameterised queries and prepared statements separate SQL code from user-supplied data, so input is bound as values rather than concatenated into statements. The database never interprets injected text as executable SQL, satisfying the primary defence requirement against SQL injection.
Why this answer
Effective mitigation of SQL injection requires separating user-supplied data from executable query statements. Parameterized queries enforce strict data typing and prevent interpreters from executing user input as code, while robust input validation adds a crucial defense-in-depth layer by rejecting malformed payloads before database interaction.
Exam trap
Candidates often include 'WAF' or 'encryption'. While helpful, they are not the primary defenses against SQLi; parameterized queries and input validation are the fundamental, code-level requirements for prevention.
During an incident response engagement at a healthcare portal, an analyst reviews an Apache access.log entry: GET /report.php?view=..%2f..%2f..%2f..%2fetc%2fpasswd HTTP/1.1 with a 200 response size of 1845 bytes. The application runs as www-data on Linux and the 'view' parameter is passed directly to readfile() without sanitization. Which web application injection attack class best describes what the attacker successfully executed?
A.SQL Injection, because the traversal sequence is being interpreted by the database engine
B.OS Command Injection, because readfile() ultimately invokes the operating system to open the file
C.Local File Inclusion via path traversal, allowing arbitrary file read within filesystem permissions
D.Remote File Inclusion, because the attacker supplied a path referencing a remote resource
AnswerC
The encoded ../ sequences (%2f is URL-encoded '/') combined with a 200 response of 1845 bytes indicate the readfile() call resolved outside the intended directory and returned /etc/passwd contents. Because only reading occurs and no code executes, this is LFI/path traversal, not remote code execution, and it is constrained to files readable by the www-data account.
Why this answer
The URL-encoded traversal sequence in the 'view' parameter, combined with a 200 response and non-trivial body size, shows the application returned a file outside its intended directory. Since the parameter feeds PHP's readfile() rather than a shell or database call, the correct classification is Local File Inclusion via path traversal. The impact is limited to reading files accessible to the web server's user account, which still exposes credential material such as /etc/passwd.
Exam trap
The trap here is assuming any ../ sequence indicates Remote File Inclusion or command execution, when the parameter's sink function determines whether code runs or only file contents are disclosed.
Refer to the exhibit. An application reflects user input directly into the HTML value attribute. What type of vulnerability is present?
A.SQL Injection
B.Reflected Cross-Site Scripting (XSS)
C.Command Injection
D.Insecure Direct Object Reference (IDOR)
AnswerB
The application reflects the user-supplied query parameter 'q' directly into the HTML without sanitization. An attacker can inject a payload like '" onmouseover="alert(1)" to execute code. This vulnerability occurs because the server trusts input and fails to perform context-aware encoding before sending the response to the client browser.
Why this answer
The exhibit shows input being reflected back into the HTML attribute without proper sanitization. This is a classic example of Reflected Cross-Site Scripting (XSS). Because the input is rendered inside a tag attribute, an attacker can break out of the context using quotes to execute arbitrary JavaScript.
This highlights the danger of rendering untrusted input, requiring rigorous encoding or validation strategies to ensure the browser interprets data as literal text.
Exam trap
Candidates often confuse Reflected XSS with Stored XSS or HTML injection, failing to realize that execution within an attribute context still qualifies as reflected cross-site scripting when immediately returned.
During an incident response engagement, you discover that a web application constructs LDAP search filters by concatenating user input directly into the filter string. An attacker submits the username `*)(uid=*))(|(uid=*` into the login form and successfully authenticates as the first user in the directory. Which vulnerability class does this behavior represent?
A.Server-Side Request Forgery (SSRF)
B.LDAP injection
C.XML External Entity (XXE) injection
D.Cross-Site Scripting (XSS)
AnswerB
The input `*)(uid=*))(|(uid=*` manipulates the LDAP filter structure, causing the authentication query to match any user. This is classic LDAP injection: unsanitized user input alters the filter logic, allowing the attacker to bypass authentication or enumerate directory objects. The incident handler should recognize this pattern as distinct from SQL injection, even though both involve injection into query languages.
Why this answer
The attacker's payload uses LDAP filter metacharacters to change the logic of the directory search, resulting in authentication bypass. This is LDAP injection. Incident handlers must distinguish it from SQL injection and XSS by examining the payload syntax and the affected component.
Recognizing the specific injection context guides containment and remediation, such as parameterizing LDAP queries and validating input.
Exam trap
The trap here is assuming any authentication bypass via crafted input must be SQL injection, ignoring that LDAP filters have their own syntax and injection techniques.
A security analyst is reviewing an incident where an attacker submitted a specially crafted XML document to a SOAP API endpoint. The XML included a DOCTYPE declaration with an ENTITY that referenced file:///etc/passwd. The server's response contained the contents of that file. Which vulnerability was exploited?
A.Cross-Site Scripting (XSS)
B.XML External Entity (XXE) injection
C.Server-Side Request Forgery (SSRF)
D.SQL injection
AnswerB
The attacker defined an external entity in the DOCTYPE that pointed to a local file, and the parser resolved it, returning the file's contents. This is the defining behavior of XXE injection. The SOAP endpoint accepted XML and processed the entity without disabling external entity resolution, allowing local file disclosure.
Why this answer
The attacker exploited an XML parser that resolved external entities, using a file:// URI to read /etc/passwd. This is XML External Entity injection. The SOAP endpoint failed to disable DOCTYPE processing or external entity resolution, allowing the server to disclose local files.
The other options describe different attack classes that do not match the XML entity mechanism.
Exam trap
The trap here is labeling any server-side request as SSRF, when the use of a file:// entity to read local files is specifically XXE.
An incident handler is examining a web application that stores user profiles in a MySQL database. A recent breach exposed data through a query that the application builds as: SELECT * FROM profiles WHERE username = '" + userInput + "'. The handler wants to recommend a code-level fix that eliminates this class of vulnerability. Which approach should be recommended?
A.Implement a web application firewall (WAF) rule that blocks common SQL injection patterns.
B.Limit database error messages returned to the user to prevent information leakage.
C.Use prepared statements with parameterized queries for all database interactions.
D.Escape single quotes and double quotes in user input before concatenation.
AnswerC
Prepared statements separate SQL code from data, so user input is bound as a parameter and cannot alter query structure. This eliminates the injection point regardless of input content. For the profiles query, the username would be passed via a placeholder, making classic payloads like ' OR '1'='1 ineffective. This is the definitive code-level fix for SQL injection.
Why this answer
The application concatenates user input directly into SQL, creating an injection flaw. Prepared statements with parameterized queries ensure that input is treated strictly as data, never as SQL syntax, which eliminates the vulnerability class. WAF rules, quote escaping, and error suppression are compensating or hardening measures but do not remove the root cause.
Exam trap
The trap here is choosing input escaping or a WAF as the fix, when only parameterization structurally separates code from data.
An incident handler is reviewing WAF logs and notices repeated HTTP requests to a web application where the 'Host' header contains an attacker-controlled domain, while the request line targets the legitimate application server. The application uses the Host header to construct password-reset links emailed to users. Which web application injection attack class BEST describes this activity?
A.HTTP response splitting through CRLF injection in the Host header
B.Cross-Site Request Forgery (CSRF) against the password reset endpoint
C.Server-Side Request Forgery (SSRF) via the password reset functionality
D.HTTP Host header injection leading to password reset poisoning
AnswerD
The attacker manipulates the Host header so the application embeds the attacker's domain into the password-reset URL. When a victim clicks the link, the reset token is sent to the attacker-controlled server. This matches the observed traffic and the application's behavior of using the Host header for link generation.
Why this answer
The attacker exploits the application's trust in the Host header to generate password-reset links. By setting the Host header to an attacker-controlled domain, the reset email contains a link pointing to that domain, allowing token theft. This is a classic Host header injection attack, distinct from CSRF, SSRF, and response splitting.
Exam trap
The trap here is assuming that any manipulation of the Host header automatically indicates SSRF or CSRF, when in fact the specific impact depends on how the application uses that header.
During incident response at a financial firm, an analyst discovers that a web application's login form is vulnerable to SQL injection. The backend is Microsoft SQL Server, and the application account has sysadmin rights. The attacker's payloads include ; EXEC xp_cmdshell 'whoami' -- and responses show the web server's service account name. Which immediate containment action best limits further damage while preserving evidence?
A.Immediately shut down the database server and restore it from the most recent backup.
B.Enable full SQL query logging and wait for the next attack to gather more indicators before taking action.
C.Block the attacker's source IP address at the perimeter firewall and continue monitoring.
D.Disable the xp_cmdshell extended stored procedure and revoke sysadmin from the application's database login, after capturing relevant logs and database state.
AnswerD
Removing sysadmin rights and disabling xp_cmdshell directly stops the observed command-execution path while preserving logs and database state for forensics. This containment is surgical: it addresses the exploited capability without destroying evidence. Capturing logs and state first ensures the analyst retains indicators such as the injected queries and any files created by whoami or subsequent commands.
Why this answer
The attacker leveraged sysadmin rights to run xp_cmdshell, achieving OS command execution through SQL injection. The most effective containment is to remove that capability by disabling xp_cmdshell and revoking sysadmin from the application login, while first preserving logs and database state. This stops the specific attack path without destroying evidence, unlike a full shutdown or restore.
Exam trap
The trap here is treating a full server shutdown as containment, when it actually destroys volatile evidence and does not address the root capability.
An incident handler is investigating a web application that uses a templating engine. The application allows users to submit their name, which is later rendered in a greeting page. An attacker submits the payload `{{7*7}}` and the page displays `49`. The application also exposes an endpoint that accepts a template name as a parameter. Which vulnerability is most likely present?
A.Server-Side Template Injection (SSTI)
B.Insecure deserialization
C.SQL injection
D.Reflected Cross-Site Scripting (XSS)
AnswerA
The payload `{{7*7}}` being evaluated to `49` indicates that user input is being processed as a template expression rather than plain text. This is the hallmark of Server-Side Template Injection. The additional endpoint accepting a template name increases the attack surface, potentially allowing template path traversal or remote code execution depending on the engine. Incident handlers should treat this as a high-severity finding.
Why this answer
The evaluation of `{{7*7}}` to `49` demonstrates that the application processes user input as a template expression. This is Server-Side Template Injection, which can lead to remote code execution depending on the engine. The secondary endpoint that accepts a template name further increases risk.
Incident responders should isolate the application, review template engine logs, and check for any uploaded or modified templates.
Exam trap
The trap here is mistaking template expression evaluation for harmless arithmetic or for client-side XSS, when the server-side evaluation itself is the vulnerability.
B.Reflected XSS is stored on the server, while Stored XSS is delivered via URLs.
C.Stored XSS permanently persists in the application, while Reflected XSS is transient.
D.Reflected XSS is more dangerous because it bypasses CSRF tokens.
AnswerC
Stored XSS payloads reside in the application's back-end storage and are served to every user who accesses the affected page. Reflected XSS payloads are transient, meaning they are processed and immediately reflected back during a single request cycle, requiring a victim to initiate the specific trigger link.
Why this answer
The difference lies in the persistence of the payload. Stored XSS injects malicious code into the server's database or permanent storage, meaning every user viewing that page is automatically affected. Reflected XSS requires the victim to click a specially crafted link that includes the payload, which is then reflected back in the response.
Understanding this distinction is vital for incident response, as Stored XSS implies a compromise of data integrity and wider impact.
Exam trap
Students often focus incorrectly on the victim delivery mechanism rather than payload persistence, confusing how the attack reaches the user with where the malicious script actually resides in storage.
An incident investigator reviews application logs showing that an attacker manipulated session tokens by altering underlying JSON Web Tokens without knowing the signing secret. The attacker successfully forged valid-looking administrative sessions. Which server-side vulnerability enabled this behavior?
A.Server-Side Request Forgery via unvalidated webhook URLs
B.Improper JWT algorithm validation permitting the 'none' signing algorithm
C.SQL injection within the session lookup table query
D.Cross-Site Scripting enabling session identifier theft from local storage
AnswerB
Failing to explicitly whitelist permitted cryptographic algorithms allows clients to specify 'none' in the JWT header. The verification library then bypasses signature checking, treating the unsigned payload as authentic and allowing total session integrity compromise.
Why this answer
Accepting JSON Web Tokens with the algorithm header set to 'none' is a critical cryptographic misconfiguration. When developers fail to enforce strict algorithm validation on the server side, attackers can strip cryptographic signatures entirely, modify payload claims, and gain unauthorized administrative privileges.
Exam trap
Candidates often blame 'weak signing keys' or 'expired tokens'. While those are issues, the specific vulnerability of the 'none' algorithm is a distinct configuration flaw that bypasses signature verification entirely.
An incident handler is investigating a web application that uses a NoSQL database (MongoDB). The attacker sent a request with the parameter 'username[$ne]=admin&password[$ne]=wrong' and successfully authenticated as an administrator. Which of the following BEST describes the attack technique used?
A.SQL injection using MongoDB's SQL compatibility layer
B.Cross-Site Scripting (XSS) through unsanitized input in the login form
C.NoSQL injection via operator injection in MongoDB query selectors
D.LDAP injection exploiting the authentication backend
AnswerC
The attacker injected MongoDB operators ($ne) into the query parameters. The application likely passed the user input directly into a MongoDB query without sanitization, allowing the attacker to alter the query logic. $ne means 'not equal', so the query returns a user where username is not 'admin' and password is not 'wrong', effectively bypassing authentication.
Why this answer
The attacker exploited the application's failure to sanitize user input before incorporating it into a MongoDB query. By injecting the $ne operator, the attacker changed the query to return a user record where the username and password are not equal to the supplied values, bypassing authentication. This is a classic NoSQL injection attack.
Exam trap
The trap here is assuming that any authentication bypass involving special characters is SQL injection, when in fact MongoDB operators indicate a NoSQL injection.
During an incident response engagement involving a web application, an analyst uncovers evidence of Command Injection. Which TWO indicators or technical conditions strongly support this specific finding? (Choose TWO)
Select 2 answers
A.Presence of shell metacharacters like pipes, ampersands, or semicolons within HTTP parameter values
E.Client-side DOM manipulation errors logged within browser developer console windows
AnswersA, C
Shell metacharacters allow attackers to chain multiple commands together in a single execution stream. Observing characters like pipes or semicolons in web server access logs strongly indicates an attempt to break out of intended application logic into the shell.
Why this answer
Command injection occurs when untrusted user input is passed directly to operating system shell interpreters via functions like system() or popen(). Analysts look for shell metacharacters such as pipes or semicolons in access logs alongside process creation anomalies indicating spawned subprocesses.
Exam trap
Candidates often select 'high CPU usage' or 'network latency'. These are generic performance issues, not specific indicators of command injection, which requires evidence of shell interaction or unexpected process spawning.
A security analyst notices that a web application reflects user-supplied input directly into an HTML attribute without encoding. An attacker crafts a URL that, when clicked by a victim, causes the victim's browser to execute a script that reads the victim's session cookie and sends it to an attacker-controlled server. Which type of attack is this?
A.Cross-Site Request Forgery (CSRF)
B.Stored Cross-Site Scripting (XSS)
C.Clickjacking
D.Reflected Cross-Site Scripting (XSS)
AnswerD
Reflected XSS occurs when user input is immediately returned by the web application in an error message, search result, or other response without proper encoding. The script executes in the victim's browser when they click the crafted URL. The theft of session cookies is a common impact. This matches the scenario exactly: input reflected into an HTML attribute, script execution, and cookie exfiltration.
Why this answer
The attack reflects user input into an HTML attribute without encoding, causing script execution in the victim's browser when they click a crafted link. This is reflected XSS. The immediate execution and cookie theft are characteristic.
Incident responders should validate input, apply context-aware output encoding, and consider Content Security Policy to mitigate such attacks.
Exam trap
The trap here is confusing reflected XSS with stored XSS by overlooking that the payload is delivered via a URL and not persisted on the server.
An incident responder analyzes a web application log and discovers that an attacker successfully extracted database schema names by manipulating a parameter where the application dynamically constructs SQL statements. The database error messages returned verbose structural details. Which remediation strategy provides the most robust defense against this injection vector while maintaining application functionality?
A.Implement client-side JavaScript validation checks to strip dangerous SQL characters before submission.
B.Configure the web application firewall to block requests containing common SQL keywords like UNION and SELECT.
C.Refactor the data access layer to utilize parameterized queries and prepared statements exclusively.
D.Disable verbose database error messages globally to prevent attackers from viewing schema details.
AnswerC
Parameterised queries and prepared statements separate SQL code from user-supplied data, so manipulated parameters are treated as values rather than executable syntax. This eliminates the injection vector at its root while preserving full query functionality, unlike input filtering or error suppression.
Why this answer
Parameterized queries decouple user-supplied input from the SQL command structure, ensuring the database engine interprets data strictly as parameters rather than executable code. This eliminates SQL injection vulnerabilities at the architectural level, regardless of input complexity or encoding techniques, protecting the underlying database management system from unauthorized data access and structural enumeration.
Exam trap
Candidates often choose input sanitization or regex filtering because they seem faster to implement, forgetting that blacklist filters can be bypassed with clever encoding or alternative syntax structures.
An organization discovers that an attacker executed operating system commands via a vulnerable web application endpoint. The application takes user input, constructs an XML payload, and passes it to an underlying XML parser without disabling external entity resolution. Which type of vulnerability enabled this command execution?
A.Server-Side Template Injection via malicious expressions evaluated by template engines
B.XML External Entity injection exploiting insecure XML parser configurations
C.Cross-Site Scripting via injected script tags within CDATA sections
D.LDAP injection through improper attribute filtering in directory search queries
AnswerB
Failing to disable Document Type Definitions and external entity resolution in XML parsers allows attackers to read local files or trigger out-of-band requests. When combined with specific PHP wrappers, XXE can escalate into direct operating system command execution.
Why this answer
XML External Entity (XXE) injection arises when applications parse untrusted XML input with external entity processing enabled. Attackers can define malicious entities referencing local system files, internal network resources, or command execution wrappers, leading to severe data compromise or remote code execution scenarios.
Exam trap
Candidates often mistake this for 'Command Injection' because command execution occurs. However, the specific vector described is the parsing of XML entities, which defines it as XXE.
Which TWO of the following techniques are most effective for preventing Cross-Site Scripting (XSS) in a web application?
Select 2 answers
A.Using contextual output encoding.
B.Implementing a strict Content Security Policy (CSP).
C.Enforcing HTTPS for all application traffic.
D.Disabling JavaScript in the web browser.
E.Using basic regex to filter out script tags.
AnswersA, B
Contextual output encoding transforms sensitive characters into their safe HTML entity equivalents before rendering data in the browser. By applying specific encoding based on where the data is placed—HTML body, attribute, or JavaScript—the application ensures the browser treats data as content rather than executable script code.
Why this answer
Preventing XSS requires a multi-layered defense strategy focused on output handling. Encoding converts potentially dangerous characters into safe representations, preventing the browser from executing them as script code. Content Security Policy provides a powerful browser-side mechanism to restrict script execution sources.
These two methods combined address both the immediate rendering risk and the long-term architectural risk of malicious scripts being injected into the DOM or executed from unauthorized domains.
Exam trap
Candidates often suggest 'input sanitization' or 'encryption'. Sanitization is often bypassed, and encryption does not prevent XSS. Contextual output encoding is the standard, effective defense mechanism.
An incident responder investigates a web application running a legacy PHP backend. Users report that searching for specific product SKUs causes the application to dump database table structures directly onto the results page. Which underlying vulnerability class is most likely responsible for this behavior?
A.Cross-Site Scripting via injected JavaScript payloads in the SKU search field
B.Error-based SQL injection via unescaped search input processed directly by the database engine
C.Remote Code Execution via insecure deserialization of serialized PHP objects
D.XML External Entity injection via malformed search queries processed by an XML parser
AnswerB
Unsanitized user inputs concatenated directly into SQL query strings allow attackers to manipulate execution flow and trigger database errors. Verbose database exceptions outputted to the user interface reveal structural details, making error-based SQL injection the primary suspect for this specific application behavior.
Why this answer
Error-based SQL injection occurs when database error messages are displayed directly to the end user through the web interface. Attackers leverage these verbose debugging messages to extract database schemas, table names, and sensitive column contents piece by piece. Remediating this requires implementing custom error handling and parameterized queries globally.
Exam trap
Candidates often confuse 'SQL Injection' with 'Information Disclosure'. While the result is information disclosure, the vulnerability class responsible for the dump is specifically SQL injection via unescaped input.
An incident handler is analyzing a severe Cross-Site Scripting (XSS) incident where malicious JavaScript stole administrator session cookies. Which TWO of the following defensive configurations and practices effectively mitigate session theft risks via XSS?
Select 2 answers
A.Set the HttpOnly flag on all sensitive authentication and session cookies.
B.Require strict TLS 1.3 encryption for all incoming and outgoing web traffic sessions.
D.Store user session tokens inside local storage rather than standard browser cookies.
E.Encode all dynamic output using generic HTML entity encoding routines on the server side.
AnswersA, C
Enabling the HttpOnly attribute instructs browsers to restrict cookie access exclusively to the HTTP protocol. Consequently, malicious JavaScript running inside an exploited browser session cannot read or exfiltrate the session identifier via document.cookie properties during an XSS attack.
Why this answer
Applying the HttpOnly flag prevents client-side scripts from accessing sensitive cookies via document.cookie, stopping direct session hijacking even if XSS exists. Combining this with a strong Content Security Policy restricts where scripts load and execute, providing defense-in-depth against malicious script injection attempts.
Exam trap
Many test-takers select encryption mechanisms or HTTPS enforcement thinking they protect session cookies from XSS, forgetting that encryption only secures data in transit.
A GCIH analyst is reviewing web server logs and sees repeated requests to /search?q=... where the q parameter contains strings like ../../../etc/passwd and ....//....//etc/shadow. The responses include root:x:0:0 entries. The application is a Java servlet that concatenates a user-supplied filename onto a base directory before calling new File(baseDir + userInput). Which vulnerability class best describes this incident?
A.XML External Entity (XXE) injection
B.Local File Inclusion (LFI)
C.Server-Side Request Forgery (SSRF)
D.Path Traversal
AnswerD
The attacker is using ../ sequences to escape the intended base directory and read files outside it, which is classic Path Traversal. The Java code concatenates user input directly onto a base path without canonicalization or a whitelist, so the servlet opens /etc/passwd instead of a permitted file. The presence of root:x:0:0 in responses confirms successful traversal, making Path Traversal the accurate classification.
Why this answer
The attacker manipulates a filename parameter to escape the intended directory using ../ sequences and reads /etc/passwd, which is the defining behavior of Path Traversal. The vulnerable Java code concatenates user input onto a base path without canonicalization or validation, allowing the traversal. SSRF, LFI, and XXE each involve different mechanisms and would not produce this specific log pattern.
Exam trap
The trap here is confusing Path Traversal with Local File Inclusion, when the servlet directly reads a file rather than including it as executable code.
Refer to the exhibit. If an attacker successfully injects <script>alert(1)</script> into a page, what happens?
A.The script executes successfully.
B.The browser blocks the script and logs a violation.
C.The browser executes the script only if the user is an admin.
D.The browser automatically strips the script tags.
AnswerB
The policy strictly restricts scripts to the origin and a specific CDN. Inline scripts are not allowed by the policy, so the browser identifies the violation, stops the script from running, and sends a report to the configured CSP reporting endpoint. This protects users from the malicious script execution.
Why this answer
The CSP policy explicitly permits only scripts from the application's own origin ('self') and from the trusted CDN. Because the injected inline script does not match these sources, the browser will block its execution. This is a crucial security control because it forces the developer to rely on external files, rendering traditional inline XSS payloads useless.
It effectively mitigates the risk by ensuring only scripts from trusted, verified locations can run.
Exam trap
Candidates often assume the script executes because they focus on the injection attempt itself rather than the active CSP policy that explicitly prevents such execution in the browser.
An incident handler is analyzing a web application that uses a NoSQL database. The application constructs queries by directly embedding user input into JSON objects. An attacker submits a payload that includes `$ne` and `$gt` operators to bypass authentication. Which TWO of the following statements accurately describe this attack or its mitigation? (Choose two.)
Select 2 answers
A.The attack is only possible if the application uses MongoDB; other NoSQL databases are immune.
B.The attack is a NoSQL injection that exploits the lack of input sanitization in query operators.
C.The attack can be mitigated by enabling strict mode in the NoSQL database, which blocks all operator usage.
D.The attack is a form of SQL injection because NoSQL databases use SQL-like syntax.
E.The attack can be prevented by using parameterized queries or an ORM that safely handles user input.
AnswersB, E
NoSQL injection occurs when user input is not properly sanitized before being included in a NoSQL query. Operators like `$ne` (not equal) and `$gt` (greater than) can alter query logic. For example, injecting `{"$ne": null}` into a password field can bypass authentication by matching any non-null value. This statement correctly identifies the attack type and its root cause.
Why this answer
NoSQL injection exploits unsanitized input that is interpreted as query operators, allowing authentication bypass or data manipulation. Effective mitigation includes using parameterized queries or ORMs, and sanitizing input to remove special operators. Incident handlers should review application code for direct concatenation of user input into NoSQL queries and check database logs for unusual operator usage.
Exam trap
The trap here is assuming NoSQL databases are immune to injection because they do not use SQL, when in fact they have their own injection vectors via query operators.
A GCIH analyst is investigating a web application that uses Java deserialization to process user-supplied session objects. The analyst suspects an attacker exploited an insecure deserialization vulnerability to achieve remote code execution. Which two indicators are most likely to confirm this type of attack? (Choose two.)
Select 2 answers
A.HTTP requests containing serialized Java objects with the magic bytes AC ED 00 05 in the body.
B.The presence of a new administrator account created in the application's user database.
D.Unexpected outbound network connections from the application server to an external IP address shortly after a suspicious request.
E.A sudden increase in the number of 404 errors for static image files.
AnswersA, D
Java serialization streams begin with the magic bytes AC ED 00 05. Their presence in HTTP request bodies indicates that the application is accepting serialized Java objects from the client. When combined with other suspicious behavior, this is a strong indicator of an insecure deserialization attack attempt, as attackers must deliver a serialized payload to the vulnerable endpoint.
Why this answer
Insecure deserialization attacks require delivering a serialized payload, which for Java begins with the AC ED 00 05 magic bytes. Successful exploitation often results in remote code execution, frequently followed by outbound connections for command-and-control or exfiltration. These two indicators together confirm both the delivery and the impact, whereas the other options are either unrelated or nonspecific.
Exam trap
The trap here is selecting generic compromise indicators like a new admin account, which can result from many attacks and do not specifically confirm deserialization exploitation.
When evaluating potential SQL injection in an application, what is the most significant indicator that an application is vulnerable?
A.The application uses a relational database management system.
B.User input is directly concatenated into a query string.
C.The database contains sensitive user data.
D.The application is written in an interpreted language.
AnswerB
String concatenation allows attackers to inject SQL syntax directly into the final command sent to the database. By using quotes and operators, an attacker can escape the data field and alter the query logic. This is the root cause of most SQL injection vulnerabilities in legacy and poorly written applications.
Why this answer
The most definitive indicator is the presence of dynamic SQL construction using unsanitized user input. When developers concatenate strings to build queries, the database cannot distinguish between data and command intent. Identifying code patterns where user parameters are directly appended to a SQL string is a critical step in security assessments.
This practice allows attackers to manipulate the query structure, leading to unauthorized data exposure, bypasses, or administrative actions within the database management system.
Exam trap
Candidates often look for 'lack of error handling' or 'verbose logs'. These are indicators of existing vulnerabilities, but direct string concatenation is the actual root cause of SQL injection.
An incident handler is investigating a web application that allows users to upload profile pictures. The application stores uploaded files in a directory accessible via the web and uses the original filename without sanitization. An attacker uploads a file named `shell.php.jpg` containing PHP code. The server executes the file when accessed via its URL. Which vulnerability has been exploited?
A.Directory Traversal
B.Local File Inclusion (LFI)
C.Remote File Inclusion (RFI)
D.Unrestricted File Upload
AnswerD
The application fails to validate the file type and allows a file with a double extension to be stored and executed. The attacker bypasses a naive check for `.jpg` by including `.php` before it. This is a classic Unrestricted File Upload vulnerability, leading to remote code execution. Incident handlers should treat this as a critical finding and review upload validation logic.
Why this answer
The application allows an attacker to upload a file with a double extension and then executes it, resulting in remote code execution. This is an Unrestricted File Upload vulnerability. Mitigations include validating file types by content, not just extension, storing uploads outside the web root, and disabling script execution in upload directories.
Incident responders should inspect upload logs and file system for malicious files.
Exam trap
The trap here is focusing on the double extension as a bypass of a specific filter, when the root issue is the lack of proper file type validation and execution prevention.
An incident responder investigates a web application breach where an attacker successfully extracted sensitive user data by appending UNION SELECT statements to a numeric product ID parameter. Which backend remediation approach directly eliminates this vulnerability class while preserving application functionality?
A.Implement client-side JavaScript regex validation to strip SQL keywords from input parameters before transmission.
B.Wrap all user inputs inside custom string-escaping functions designed to neutralize single quotes and semicolons.
C.Refactor database queries to use prepared statements with bound parameters via the application data access layer.
D.Deploy a traditional network firewall configured with signature rules to block incoming HTTP GET requests containing UNION.
AnswerC
Prepared statements separate code and data completely at the database driver level. When parameters are bound correctly, any user-supplied string like a UNION query is treated strictly as literal literal data values, neutralizing injection attempts and protecting backend data assets permanently.
Why this answer
Parameterized queries decouple user-supplied input from the SQL command structure, ensuring the database engine treats input exclusively as data rather than executable code. Implementing parameterized queries globally stops SQL injection by neutralizing untrusted input regardless of characters appended by attackers, making it the definitive defense for database interaction security in incident response hardening.
Exam trap
Candidates often confuse input sanitization or escaping with parameterized queries, assuming that stripping dangerous characters like quotes provides complete protection against advanced SQL injection variants.
B.It allows attackers to inject malicious code into the database.
C.It facilitates the execution of arbitrary code via gadget chains.
D.It causes the application to leak internal memory structures.
AnswerC
Attackers can craft malicious serialized objects that, when deserialized, trigger a sequence of method calls known as gadget chains. These chains utilize existing application code to perform unintended actions, leading to full remote code execution. This makes it a high-severity risk in applications that accept serialized data from users.
Why this answer
Insecure deserialization occurs when untrusted data is used to abuse the logic of an application, inflict a DoS, or execute arbitrary code. By manipulating the serialized object, an attacker can modify application state, bypass authentication, or leverage existing application code (gadget chains) to gain remote code execution. This is critical because modern frameworks often automatically deserialize objects from user-provided data without sufficient verification or integrity checks on the source.
Exam trap
Candidates often confuse insecure deserialization with standard injection attacks like SQLi, failing to recognize that the core danger specifically stems from abusing application logic and leveraging gadget chains to achieve arbitrary code execution.
During a web application penetration test, an assessor discovers an endpoint vulnerable to OS Command Injection via an improperly sanitized ping utility parameter. Which TWO remediation strategies provide robust defense against command injection vulnerabilities?
Select 2 answers
A.Replace shell execution wrappers with native language libraries or built-in functions designed for the specific task.
B.Apply strict input validation blacklists to filter out dangerous shell operators such as semicolons, pipes, and ampersands.
C.Pass command arguments as separate array elements to process execution functions instead of a single string.
D.Configure the web server process to run with elevated root privileges to ensure access to system binaries.
E.Encode all user inputs using URL encoding standards before passing parameters into system shell execution functions.
AnswersA, C
Native language libraries or built-in functions perform the intended task without invoking a shell, eliminating the command interpreter that enables injection. This satisfies the stem's requirement for robust remediation by removing the vulnerable mechanism entirely, rather than filtering or escaping user input.
Why this answer
Replacing insecure OS command execution functions with native language libraries or APIs completely avoids invoking the underlying operating system shell. When OS execution is strictly necessary, passing arguments as a fixed array rather than a concatenated string prevents shell metacharacter interpretation.
Exam trap
Test-takers often choose input blacklisting of characters like semicolons or pipes, ignoring the fact that attackers easily find alternative shell delimiters.