SSCP Systems and Application Security Practice Question
A security analyst is reviewing a web application for OWASP Top 10 vulnerabilities. Which THREE of the following are examples of injection flaws?
⚠ Common exam trap
SSCP often tests whether candidates lump XSS into the injection category — XSS is injection-adjacent but OWASP lists it separately, so selecting it as a 'server-side injection' example is the classic wrong answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SQL injection
SQL injection (A) is a classic injection flaw where untrusted input is concatenated into SQL statements, allowing an attacker to alter query logic and manipulate the database. LDAP injection (B) is also an injection flaw because unsanitized input inserted into LDAP filters or queries can modify directory lookups and bypass authentication or expose directory data. OS command injection (D) occurs when user input is passed to a shell or system call, letting an attacker execute arbitrary operating-system commands on the server. Broken authentication (C) is a separate OWASP category involving weaknesses in session management, credential handling, or authentication logic, not an injection flaw. Cross-Site Scripting (E) is typically classified under injection-like client-side flaws or its own category, but in the OWASP Top 10 it is not grouped as an injection flaw in the same sense as SQL, LDAP, or OS command injection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SQL injection
Why this is correct
SQL injection inserts malicious SQL statements through unsanitised input fields, tricking the database interpreter into executing attacker-controlled queries. It is a canonical injection flaw because untrusted data crosses into an interpreter without proper separation, matching the OWASP Top 10 category.
- ✓
LDAP injection
Why this is correct
LDAP injection embeds crafted filter syntax in input fields, altering directory queries the application sends to the LDAP server. As with other injection flaws, unsanitised user data is interpreted as code by the directory service, satisfying the OWASP Top 10 injection category.
- ✗
Broken authentication
Why it's wrong here
Broken authentication is a distinct OWASP category covering session and credential weaknesses, not injection, which requires untrusted input being interpreted as code or commands. The option tempts because both are access-control-adjacent flaws found in the same Top 10 list. Injection specifically involves unsanitised data reaching an interpreter such as SQL, LDAP, or the OS.
- ✓
OS command injection
Why this is correct
OS command injection passes shell metacharacters through application input so the underlying operating system executes arbitrary commands. Untrusted data reaches a command interpreter without sanitisation, which is precisely the injection mechanism the OWASP Top 10 describes.
- ✗
Cross-Site Scripting (XSS)
Why it's wrong here
Cross-Site Scripting is classified under its own OWASP category, not injection, despite sharing the root cause of unescaped user input. The option tempts because XSS does involve injecting script into pages, and many practitioners loosely call it injection. OWASP separates them because XSS targets the victim's browser, whereas injection flaws target server-side interpreters.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security analyst is reviewing OWASP Top 10 vulnerabilities in a web application. Which TWO are injection-related attacks? (Select TWO.)
hard- A.Security Misconfiguration
- ✓ B.Cross-Site Scripting (XSS)
- C.Cross-Site Request Forgery (CSRF)
- D.Insecure Direct Object References (IDOR)
- ✓ E.SQL injection
Why B: Cross-Site Scripting (XSS) (B) is correct because it is an injection attack in which attacker-supplied JavaScript is injected into a web page and executed in a victim's browser, typically via unescaped user input rendered into HTML, allowing session theft or DOM manipulation. SQL injection (E) is correct because it injects malicious SQL statements through unsanitized input into a database query, enabling data exfiltration, authentication bypass, or command execution on the DBMS. Both belong to the injection class of attacks where untrusted data is interpreted as code or commands by an interpreter. Security Misconfiguration (A) is a configuration weakness, not an injection flaw. Cross-Site Request Forgery (CSRF) (C) abuses a victim's authenticated session to force unintended requests, not code injection. Insecure Direct Object References (IDOR) (D) is an access-control flaw where object identifiers are manipulated to reach unauthorized resources, not an injection attack.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.