Courseiva

SSCP Systems and Application Security Practice Question

A security analyst is reviewing OWASP Top 10 vulnerabilities in a web application. Which TWO are injection-related attacks? (Select TWO.)

⚠ Common exam trap

The trap here is that candidates see 'web application attack' and lump CSRF or IDOR in with injection, forgetting that injection specifically requires untrusted input being interpreted as code by a parser or engine.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS) (B) is correct because it is an injection attack in which attacker-supplied JavaScript is injected into a web page and executed in a victim's browser, typically via unescaped user input rendered into HTML, allowing session theft or DOM manipulation. SQL injection (E) is correct because it injects malicious SQL statements through unsanitized input into a database query, enabling data exfiltration, authentication bypass, or command execution on the DBMS. Both belong to the injection class of attacks where untrusted data is interpreted as code or commands by an interpreter. Security Misconfiguration (A) is a configuration weakness, not an injection flaw. Cross-Site Request Forgery (CSRF) (C) abuses a victim's authenticated session to force unintended requests, not code injection. Insecure Direct Object References (IDOR) (D) is an access-control flaw where object identifiers are manipulated to reach unauthorized resources, not an injection attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security Misconfiguration

    Why it's wrong here

    Security Misconfiguration is a distinct OWASP category covering insecure defaults, verbose errors and unnecessary features, not untrusted data passed to an interpreter. It is tempting because misconfiguration often enables injection flaws, but the injection categories themselves are specifically SQL injection and cross-site scripting, which arise from unsanitised input.

  • ✓

    Cross-Site Scripting (XSS)

    Why this is correct

    Cross-Site Scripting injects malicious scripts into content served to other users, exploiting unvalidated input rendered without output encoding. This satisfies the injection criterion: untrusted data is interpreted as executable code by the victim's browser, distinct from server-side SQL or command injection, but still an injection flaw within the OWASP Top 10.

  • ✗

    Cross-Site Request Forgery (CSRF)

    Why it's wrong here

    CSRF exploits a victim's authenticated session to submit forged requests; it injects no malicious payload into an interpreter, so it is a broken-access-control flaw. It is tempting because CSRF does abuse user input and request parameters, and would be correct in a question about session-riding or request-forgery attacks rather than injection.

  • ✗

    Insecure Direct Object References (IDOR)

    Why it's wrong here

    IDOR manipulates an object reference to reach another user's record; no interpreter parses attacker-supplied data, so it is broken access control, not injection. It is tempting because IDOR does involve tampering with user-controlled input, and would be correct in a question about authorisation flaws rather than injection attacks.

  • ✓

    SQL injection

    Why this is correct

    SQL injection manipulates untrusted input so it is interpreted as database commands, directly satisfying the injection-related attack criterion. It sits in the OWASP Top 10 under Injection (A03), alongside cross-site scripting, because both exploit unvalidated input reaching an interpreter. This matches the stem's requirement for an injection vulnerability.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.