Courseiva

CCNA Systems and Application Security Questions

26 of 101 questions · Page 2/2 · Systems and Application Security · Answers revealed

76
MCQmedium

A security administrator is configuring a Linux server to enforce mandatory access control (MAC). Which of the following tools provides MAC on Linux?

A.PAM
B.iptables
C.chmod
D.SELinux
AnswerD

SELinux enforces mandatory access control through type enforcement, role-based access control and multi-level security, applying kernel-level policy labels that constrain every process and file regardless of user discretion. AppArmor and standard permissions do not provide the same comprehensive MAC model on Linux.

Why this answer

SELinux and AppArmor are Linux security modules that implement mandatory access control policies beyond traditional discretionary access control.

77
Multi-Selectmedium

A cloud security architect is designing a solution to protect workloads running in a public cloud. Which THREE of the following are key security controls that should be implemented?

Select 3 answers
A.Store encryption keys in the same cloud region as the data
B.Deploy a Cloud Security Posture Management (CSPM) tool
C.Disable multi-factor authentication for service accounts
D.Use a Cloud Workload Protection Platform (CWPP)
E.Implement IAM roles with least privilege
AnswersB, D, E

CSPM continuously assesses cloud configuration against benchmarks and compliance baselines, detecting misconfigured storage, network and logging settings. It satisfies the stem's design requirement by addressing the misconfiguration risk inherent to public cloud, where provider-managed infrastructure removes traditional perimeter controls.

Why this answer

Option B is correct because a Cloud Security Posture Management (CSPM) tool continuously monitors the cloud environment for misconfigurations, compliance violations, and policy drift, which is a foundational control for protecting public cloud workloads. Option D is correct because a Cloud Workload Protection Platform (CWPP) secures the actual workloads (VMs, containers, serverless functions) at runtime, providing vulnerability scanning, threat detection, and workload-level hardening. Option E is correct because implementing IAM roles with least privilege limits each identity to only the permissions required for its function, reducing the blast radius of compromised credentials and enforcing zero-trust access control.

Option A is not a key control because storing encryption keys in the same region as the data does not improve security and may actually reduce resilience; key management should follow a dedicated KMS/HSM strategy with appropriate separation and replication. Option C is not a key control because disabling multi-factor authentication for service accounts weakens security and violates best practices; MFA or strong credential management should be enforced, not removed.

Exam trap

The trap is that some options sound plausible but are either not security controls (A) or are insecure practices (C). Candidates might also overlook that the question asks for THREE, and E is correct but easy to miss if they focus only on the first two.

78
Multi-Selecthard

A security analyst is reviewing a web application for OWASP Top 10 vulnerabilities. Which THREE of the following are examples of injection flaws?

Select 3 answers
A.SQL injection
B.LDAP injection
C.Broken authentication
D.OS command injection
E.Cross-Site Scripting (XSS)
AnswersA, B, D

SQL injection inserts malicious SQL statements through unsanitised input fields, tricking the database interpreter into executing attacker-controlled queries. It is a canonical injection flaw because untrusted data crosses into an interpreter without proper separation, matching the OWASP Top 10 category.

Why this answer

SQL injection (A) is a classic injection flaw where untrusted input is concatenated into SQL statements, allowing an attacker to alter query logic and manipulate the database. LDAP injection (B) is also an injection flaw because unsanitized input inserted into LDAP filters or queries can modify directory lookups and bypass authentication or expose directory data. OS command injection (D) occurs when user input is passed to a shell or system call, letting an attacker execute arbitrary operating-system commands on the server.

Broken authentication (C) is a separate OWASP category involving weaknesses in session management, credential handling, or authentication logic, not an injection flaw. Cross-Site Scripting (E) is typically classified under injection-like client-side flaws or its own category, but in the OWASP Top 10 it is not grouped as an injection flaw in the same sense as SQL, LDAP, or OS command injection.

Exam trap

SSCP often tests whether candidates lump XSS into the injection category — XSS is injection-adjacent but OWASP lists it separately, so selecting it as a 'server-side injection' example is the classic wrong answer.

79
MCQeasy

A developer is building a mobile banking application and wants to ensure that if an attacker gains physical access to a rooted or jailbroken device, the application's sensitive data stored locally cannot be easily read. The developer decides to use the secure storage provided by the mobile operating system. Which of the following BEST describes the protection offered by this secure storage?

A.Data is encrypted with a hardware-backed key stored in a secure element or trusted execution environment.
B.Data is encrypted with a key derived from the user's login password, which is never stored on the device.
C.Data is stored in a hidden directory that is inaccessible to other applications due to sandbox permissions.
D.Data is obfuscated using a proprietary algorithm that changes with each application release to prevent reverse engineering.
AnswerA

Mobile OS secure storage, such as iOS Keychain or Android Keystore, uses hardware-backed keys in a secure element or trusted execution environment. The key material is protected from software attacks, and even on a rooted or jailbroken device, extracting the key is significantly harder. This matches the protection the developer seeks for locally stored sensitive data.

Why this answer

Mobile operating systems provide secure storage such as iOS Keychain and Android Keystore, which encrypt data with hardware-backed keys stored in a secure element or trusted execution environment. This protects sensitive data even on rooted or jailbroken devices because the key cannot be easily extracted. Password-derived keys, obfuscation, and sandbox permissions do not provide equivalent protection against a privileged attacker.

Exam trap

The trap here is treating application sandboxing as sufficient protection, when a rooted or jailbroken device allows an attacker to bypass sandbox restrictions.

80
Multi-Selecthard

A security administrator is implementing application whitelisting on a fleet of Linux servers that run a fixed set of approved binaries. The administrator wants to ensure only authorized executables can run, while still allowing legitimate administrative scripts. Which TWO of the following approaches BEST support this goal? (Choose two.)

Select 2 answers
A.Enable a host-based intrusion detection system that alerts on execution of unknown binaries.
B.Mount the application directories as read-only and restrict write access to root only.
C.Use an integrity measurement and attestation mechanism that records hashes of approved binaries and blocks execution of unlisted files.
D.Deploy mandatory access control policy that confines each service to a profile permitting only its required executables.
E.Configure a cron job that periodically compares running processes against a known-good list and kills anomalies.
AnswersC, D

Integrity measurement with attestation verifies that only binaries matching approved hashes execute, which directly enforces whitelisting. It also provides evidence that the system has not been tampered with. This approach supports the requirement to allow approved binaries while blocking unauthorized executables, and it can be integrated with boot-time verification for stronger assurance.

Why this answer

Effective application whitelisting on Linux relies on preventive controls that stop unapproved executables before they run. Integrity measurement with attestation and mandatory access control profiles both enforce an allowlist at execution time, while still permitting approved administrative scripts when properly configured. Detection and hardening measures are useful complements but do not by themselves guarantee that only authorized binaries execute.

Exam trap

The trap here is selecting detective or hardening measures that reduce risk but do not actually block execution of unauthorized binaries, which is what whitelisting requires.

81
MCQmedium

A security administrator is reviewing Linux audit logs to detect unauthorized file access. Which Linux component is primarily responsible for generating these security audit logs?

A.systemd-journald
B.SELinux
C.PAM
D.auditd
AnswerD

The auditd daemon is the Linux userspace component that writes kernel-generated audit events to /var/log/audit/audit.log, capturing file access, syscalls and authentication activity. It is the subsystem specifically responsible for producing the security audit records the administrator reviews.

Why this answer

auditd is the userspace component of the Linux Audit system that writes audit records to disk.

82
Multi-Selectmedium

An organization uses Linux servers and wants to implement mandatory access control (MAC) to enhance security. Which TWO technologies can be used? (Select TWO.)

Select 2 answers
A.SELinux
B.iptables
C.AppArmor
D.auditd
E.PAM (Pluggable Authentication Modules)
AnswersA, C

SELinux enforces mandatory access control through kernel-level type enforcement and security contexts, applying policy defined by the administrator rather than the resource owner. This satisfies the Linux MAC requirement because even root processes are confined by the loaded policy.

Why this answer

SELinux (A) is correct because it is a Linux kernel security module that enforces mandatory access control by applying type enforcement, role-based access control, and multi-level security policies that confine processes and users regardless of their discretionary permissions. AppArmor (C) is also correct because it implements MAC through per-program profiles that restrict an application's file, network, and capability access using path-based rules loaded into the kernel. iptables (B) is incorrect because it is a packet-filtering firewall tool for network traffic, not a MAC framework for constraining process privileges. auditd (D) is incorrect because it is the Linux auditing daemon that logs security-relevant events, providing accountability rather than access enforcement. PAM (E) is incorrect because it is an authentication framework that handles login and credential checks, not a mandatory access control mechanism.

Exam trap

SSCP often tests the distinction between MAC frameworks (SELinux, AppArmor) and adjacent security tools (iptables for firewalling, auditd for auditing, PAM for authentication) — candidates pick familiar tools without confirming they enforce MAC.

83
Multi-Selectmedium

A security administrator is reviewing how mobile devices connect to corporate email and file shares. The organization wants to protect data if a device is lost and to prevent data leakage between personal and work applications. Which TWO controls should the administrator implement? (Choose two.)

Select 2 answers
A.Enable full device backup to the user's personal cloud account
B.Enroll devices in a mobile device management solution with remote wipe
C.Configure containerization that separates corporate apps and data from personal apps
D.Allow sideloading of applications from unknown sources
E.Disable device encryption to improve application performance
AnswersB, C

MDM enrollment lets the organization enforce policy, monitor compliance, and trigger a remote wipe if a device is lost, directly addressing the data protection requirement. It also provides the management channel needed to push other controls such as passcode and encryption policies to enrolled devices.

Why this answer

MDM with remote wipe protects data when a device is lost, and containerization isolates corporate apps and data from personal ones to stop leakage across the boundary. Together they address both parts of the requirement without forcing users to carry separate devices.

Exam trap

The trap here is selecting convenience features such as personal cloud backup or sideloading, which feel helpful but actually expand data exposure and defeat the stated goals.

84
MCQhard

During a code review, a developer identifies that a web application directly concatenates user input into SQL queries without sanitization. This vulnerability is classified under which OWASP Top 10 category?

A.Cross-Site Scripting (XSS)
B.Security Misconfiguration
C.Broken Access Control
D.Injection
AnswerD

Concatenating unsanitised input into SQL queries lets attackers alter query structure, so the flaw is Injection. This directly satisfies the stem's constraint: user input reaches an interpreter without sanitisation. Injection covers SQL, NoSQL, OS command and ORM injection, making it the precise OWASP Top 10 category here.

Why this answer

Directly concatenating unsanitized user input into SQL queries is the textbook definition of SQL injection, which falls under the OWASP Top 10 'Injection' category (A03:2021). Injection covers SQL, NoSQL, OS command, and LDAP injection where untrusted data is interpreted as code or commands. The fix is parameterized queries or prepared statements, not input filtering alone.

Exam trap

The trap here is that candidates see 'web application' and 'user input' and jump to XSS, but the key discriminator is that the input reaches a SQL query, which is Injection, not Cross-Site Scripting.

How to eliminate wrong answers

Option A is wrong because XSS involves injecting client-side script into web pages viewed by other users, not manipulating backend SQL queries. Option B is wrong because Security Misconfiguration refers to insecure default settings, verbose errors, or unnecessary features enabled, not unsanitized query construction. Option C is wrong because Broken Access Control concerns users acting outside their intended permissions, not the injection of malicious SQL through input fields.

85
MCQmedium

Which of the following tools would best help a security team detect misconfigurations in a cloud environment, such as open storage buckets or overly permissive IAM roles?

A.Cloud Security Posture Management (CSPM)
B.Web Application Firewall (WAF)
C.Cloud Workload Protection Platform (CWPP)
D.Event Viewer
AnswerA

CSPM tools continuously scan cloud configurations against benchmarks and policies, surfacing open storage buckets and overly permissive IAM roles. This agentless posture assessment targets exactly the misconfiguration class described, unlike runtime workload protection or vulnerability scanners.

Why this answer

Cloud Security Posture Management (CSPM) tools are specifically designed to continuously monitor cloud environments for misconfigurations, compliance violations, and security risks such as open storage buckets and overly permissive IAM roles. They compare the actual configuration against best practices and benchmarks (e.g., CIS, NIST) and alert on deviations. This directly addresses the need to detect misconfigurations.

Exam trap

The trap is confusing CSPM with CWPP or WAF; candidates may think any cloud security tool detects misconfigurations, but only CSPM is purpose-built for posture management.

How to eliminate wrong answers

Option B is wrong because a Web Application Firewall protects web applications from HTTP-based attacks like SQL injection and XSS, but it does not assess cloud infrastructure configurations. Option C is wrong because a Cloud Workload Protection Platform focuses on securing workloads (VMs, containers, serverless) at runtime, including vulnerability management and threat detection, but not on cloud service configuration posture. Option D is wrong because Event Viewer is a Windows logging tool for local system events, not a cloud configuration scanner.

86
MCQmedium

An administrator wants to ensure that a Linux web server only allows the www-data user to run specific commands with elevated privileges. Which configuration file should be modified?

A./etc/sudoers
B./etc/pam.d/
C./etc/chmod.conf
D./etc/selinux/config
AnswerA

The /etc/sudoers file defines which users may run which commands with elevated privileges, so a rule granting www-data only specific commands enforces least privilege. Editing it via visudo validates syntax and prevents locking out administrative access.

Why this answer

The /etc/sudoers file defines which users or groups may run which commands with elevated privileges via sudo. To allow www-data to run specific commands as root, you add entries there (typically using visudo). This enforces least privilege by limiting the commands the web user can execute with sudo.

Exam trap

SSCP often tests file-path knowledge; candidates confuse authentication configuration (PAM) with authorization for command execution (sudoers), or pick SELinux config thinking it controls privileges.

How to eliminate wrong answers

Option B is wrong because /etc/pam.d/ contains PAM configuration files for authentication, authorization, and session modules, not command-level sudo permissions. Option C is wrong because /etc/chmod.conf does not exist as a standard Linux configuration file; chmod is a command, not a config file. Option D is wrong because /etc/selinux/config controls SELinux mode (enforcing, permissive, disabled), not sudo command permissions.

87
MCQmedium

A Windows system administrator needs to enforce a security policy that prevents users from installing unauthorized software. Which feature should be configured via Group Policy?

A.Windows Defender Firewall
B.User Account Control (UAC)
C.AppLocker
D.BitLocker Drive Encryption
AnswerC

AppLocker applies allow or deny rules based on publisher, path, or file hash, blocking execution of unauthorised installers and applications. Configured through Group Policy, it directly enforces the software restriction the administrator needs, unlike firewall or audit settings.

Why this answer

AppLocker is a Windows application control feature configured via Group Policy that lets administrators allow or deny which applications and files users can run, directly preventing installation and execution of unauthorized software. It uses rules based on publisher, path, or file hash. This is the correct tool for enforcing an application allowlist/denylist through GPO.

Exam trap

SSCP often tests endpoint security controls, and candidates confuse UAC (elevation prompts) with AppLocker (application execution control), picking UAC when the requirement is preventing unauthorized software installation.

How to eliminate wrong answers

Option A is wrong because Windows Defender Firewall controls network traffic (ports, protocols, IPs), not which applications users can install or run. Option B is wrong because User Account Control prompts for elevation but does not block installation of unauthorized software if the user has admin rights or if the installer runs without elevation. Option D is wrong because BitLocker encrypts disk volumes to protect data at rest, not to control application execution.

88
MCQmedium

An organization is implementing Windows Defender Application Control (WDAC) to prevent unauthorized applications from running on company workstations. Which of the following best describes the primary security benefit of this approach?

A.It prevents execution of any application not explicitly allowed
B.It encrypts application binaries at rest
C.It automatically updates applications from a trusted source
D.It ensures that all applications are digitally signed
AnswerA

WDAC enforces an allowlist model: only applications matching explicitly permitted publisher, hash or path rules may execute, blocking all else by default. This directly satisfies the requirement to prevent unauthorised applications from running, unlike audit-only or reputation-based approaches.

Why this answer

WDAC is an application control mechanism that enforces an allowlist of approved code, blocking execution of any binary, script, or package not explicitly permitted by policy. This default-deny posture is its primary security benefit, preventing unauthorized or malicious executables from running even if they land on the endpoint.

Exam trap

SSCP often tests the distinction between application allowlisting (WDAC) and adjacent controls like encryption, patching, or code signing, baiting candidates who conflate prevention of execution with integrity or confidentiality controls.

How to eliminate wrong answers

Option B is wrong because WDAC does not encrypt binaries at rest — that is the role of BitLocker or similar full-disk encryption technologies. Option C is wrong because WDAC does not perform application updates; patching is handled by tools like Intune, WSUS, or Configuration Manager. Option D is wrong because WDAC does not require all applications to be digitally signed — it can allow unsigned code via hash rules or explicit file path rules, though signing is a recommended best practice.

89
MCQmedium

A security analyst is reviewing logs from a web application and notices numerous requests with the following pattern: GET /products?category=1' OR '1'='1. The analyst suspects a SQL injection attack. Which of the following is the MOST effective control to prevent this type of attack?

A.Deploy a web application firewall (WAF) to block SQL injection patterns.
B.Use parameterized queries (prepared statements) for all database access.
C.Implement input validation to reject requests containing single quotes.
D.Store the database in a read-only mode to prevent data modification.
AnswerB

Parameterized queries ensure that user input is treated as data, not executable code, by separating SQL logic from data. This prevents attackers from altering the query structure, effectively mitigating SQL injection regardless of the input's content. It is the most effective control for this vulnerability.

Why this answer

SQL injection occurs when user input is concatenated into SQL queries, allowing attackers to alter the query logic. Parameterized queries separate the query structure from the data, ensuring that input cannot change the intended SQL command. This is the most effective and reliable prevention method, as it addresses the root cause rather than relying on detection or input filtering.

Exam trap

The trap here is relying on input validation or a WAF as the primary defense, when they can be bypassed or may not cover all injection vectors.

90
MCQeasy

An organization wants to prevent unauthorized applications from running on Windows workstations. Which Windows feature should be used to enforce application whitelisting?

A.User Account Control (UAC)
B.Windows Firewall with Advanced Security
C.Windows Defender Application Control (WDAC)
D.Windows Defender Antivirus
AnswerC

WDAC enforces application whitelisting by validating executables against code-integrity policies at the kernel level, blocking anything unsigned or untrusted. This directly satisfies the requirement to prevent unauthorised applications from running on Windows workstations, unlike AppLocker's weaker user-mode enforcement.

Why this answer

Windows Defender Application Control (WDAC) is Microsoft's application control feature that enforces application whitelisting by allowing only explicitly trusted code to run on Windows workstations. It uses code integrity policies (based on publisher, hash, or path) to block unauthorized executables, scripts, and drivers. WDAC is the modern successor to AppLocker and is built into Windows 10/11 and Windows Server.

Exam trap

SSCP often tests the distinction between preventive controls (WDAC/AppLocker) and detective controls (antivirus), so candidates who see 'prevent unauthorized applications' and pick 'Windows Defender Antivirus' fall for the detection-vs-prevention confusion.

How to eliminate wrong answers

Option A is wrong because User Account Control (UAC) only prompts for elevation when administrative privileges are requested; it does not restrict which applications can execute. Option B is wrong because Windows Firewall with Advanced Security filters network traffic by port, protocol, and IP address, not by application identity or code integrity. Option D is wrong because Windows Defender Antivirus is signature/heuristic-based malware detection, not a whitelisting enforcement mechanism — it detects known bad files rather than allowing only approved ones.

91
MCQhard

During a security assessment, an analyst finds that multiple snapshots of a critical virtual machine are stored on the hypervisor host. Some snapshots are several months old. Which risk is MOST likely?

A.VM escape via snapshot file corruption
B.Unauthorized access to snapshot data
C.Reintroduction of unpatched vulnerabilities
D.Hypervisor memory exhaustion
AnswerC

Old snapshots preserve the VM's disk state from months earlier, including operating system and application versions that have since been patched. Restoring or reverting to such a snapshot reinstates those unpatched vulnerabilities, directly satisfying the stem's concern about stale, months-old snapshots retained on the hypervisor host.

Why this answer

Old VM snapshots preserve the exact state of the VM at the time of capture, including the OS and application binaries. If a VM is reverted to a months-old snapshot, any patches applied since then are lost, reintroducing known vulnerabilities that attackers can exploit. This is the most likely and direct risk of retaining stale snapshots on the hypervisor.

Exam trap

SSCP often tests snapshot risks — candidates focus on exotic threats like VM escape or data theft, missing the mundane but most probable risk: reverting to an unpatched state.

How to eliminate wrong answers

Option A is wrong because VM escape via snapshot file corruption is a theoretical and rare attack vector, not the primary risk of stale snapshots. Option B is wrong because unauthorized access to snapshot data is a confidentiality risk that depends on access controls, not on snapshot age. Option D is wrong because hypervisor memory exhaustion is a resource management issue unrelated to the age of snapshots; snapshots consume storage, not hypervisor RAM.

92
MCQeasy

A small business wants to protect data stored on employee laptops. The security policy requires that if a laptop is lost or stolen, the data on its disk cannot be read by anyone without the proper authentication. Which of the following should be implemented?

A.A personal firewall
B.File integrity monitoring
C.Full disk encryption
D.A host-based intrusion detection system
AnswerC

Full disk encryption converts the entire drive contents into ciphertext so that data at rest is unreadable without the decryption key or authentication credential. If a laptop is lost or stolen, an attacker cannot extract files by removing the drive. This directly satisfies the requirement that lost-device data remain protected without proper authentication.

Why this answer

Full disk encryption ensures that data at rest is ciphertext and unreadable without the correct key or authentication, which is exactly the protection needed when a laptop is lost or stolen. The other controls address runtime monitoring, integrity, or network filtering and do not prevent offline disk reading. For portable devices, encryption is the foundational data-at-rest control.

Exam trap

The trap here is selecting a monitoring or network control that sounds security-related but operates only while the system is running, leaving the disk fully readable after physical theft.

93
MCQhard

During an application security review, a penetration tester discovers that a web application allows users to view other users' profiles by changing an ID parameter in the URL (e.g., /profile?id=123). Which OWASP Top 10 vulnerability does this represent?

A.Broken Authentication
B.Security Misconfiguration
C.Insecure Direct Object References (IDOR)
D.Injection
AnswerC

Manipulating the id parameter grants access to another user's profile because the application trusts client-supplied input without verifying ownership. This is IDOR: an authorisation flaw where the object reference is exposed and no access control check confirms the requester's entitlement to that record.

Why this answer

Insecure Direct Object Reference (IDOR) occurs when an application exposes an internal object identifier (like a user ID in a URL) and fails to verify that the requesting user is authorized to access that object. Changing /profile?id=123 to another ID to view another user's profile is the classic IDOR pattern. It falls under OWASP's Broken Access Control category (A01:2021).

Exam trap

SSCP often tests the confusion between Broken Authentication and Broken Access Control, so candidates who see 'changing an ID' and pick Broken Authentication miss that authentication is about identity, while IDOR is about authorization to access a specific object.

How to eliminate wrong answers

Option A is wrong because Broken Authentication refers to flaws in login, session management, or credential handling (e.g., weak password policies, session fixation), not to authorization checks on object access. Option B is wrong because Security Misconfiguration involves insecure default settings, verbose errors, or unnecessary features enabled — not missing per-object authorization. Option D is wrong because Injection involves untrusted input being interpreted as code or commands (SQLi, command injection), whereas IDOR is an access control flaw with no code execution.

94
Multi-Selecthard

A security analyst is reviewing OWASP Top 10 vulnerabilities in a web application. Which TWO are injection-related attacks? (Select TWO.)

Select 2 answers
A.Security Misconfiguration
B.Cross-Site Scripting (XSS)
C.Cross-Site Request Forgery (CSRF)
D.Insecure Direct Object References (IDOR)
E.SQL injection
AnswersB, E

Cross-Site Scripting injects malicious scripts into content served to other users, exploiting unvalidated input rendered without output encoding. This satisfies the injection criterion: untrusted data is interpreted as executable code by the victim's browser, distinct from server-side SQL or command injection, but still an injection flaw within the OWASP Top 10.

Why this answer

Cross-Site Scripting (XSS) (B) is correct because it is an injection attack in which attacker-supplied JavaScript is injected into a web page and executed in a victim's browser, typically via unescaped user input rendered into HTML, allowing session theft or DOM manipulation. SQL injection (E) is correct because it injects malicious SQL statements through unsanitized input into a database query, enabling data exfiltration, authentication bypass, or command execution on the DBMS. Both belong to the injection class of attacks where untrusted data is interpreted as code or commands by an interpreter.

Security Misconfiguration (A) is a configuration weakness, not an injection flaw. Cross-Site Request Forgery (CSRF) (C) abuses a victim's authenticated session to force unintended requests, not code injection. Insecure Direct Object References (IDOR) (D) is an access-control flaw where object identifiers are manipulated to reach unauthorized resources, not an injection attack.

Exam trap

The trap here is that candidates see 'web application attack' and lump CSRF or IDOR in with injection, forgetting that injection specifically requires untrusted input being interpreted as code by a parser or engine.

95
MCQhard

A security engineer is reviewing the configuration of a web application that uses JSON Web Tokens (JWT) for session management. The engineer notices that the application accepts tokens signed with the 'none' algorithm. Which of the following is the most critical security risk associated with this configuration?

A.Tokens will be transmitted in plaintext, exposing sensitive information.
B.Tokens will expire prematurely, causing denial of service for legitimate users.
C.The application will experience performance degradation due to lack of signature verification.
D.Attackers can forge tokens with arbitrary claims, leading to privilege escalation.
AnswerD

When the 'none' algorithm is accepted, the token's signature is not verified. An attacker can modify the token's payload, such as changing the user role to admin, and set the algorithm to 'none' to bypass signature validation. This allows forging tokens with arbitrary claims, resulting in unauthorized access and privilege escalation.

Why this answer

Accepting the 'none' algorithm means the application does not verify the token's signature. An attacker can craft a token with any claims and set the algorithm to 'none', bypassing authentication and authorization. This is a critical vulnerability that can lead to full account takeover and privilege escalation.

Exam trap

The trap here is focusing on transport or performance issues when the core risk is the loss of integrity and authenticity due to missing signature verification.

96
MCQhard

A security administrator is deploying a new web application on a Linux server and wants to prevent an attacker who compromises the web server process from reading the application's private TLS keys stored on the same host. The administrator decides to use a hardware security module (HSM) to protect the keys. Which of the following BEST describes how the HSM provides this protection?

A.The HSM stores the private keys in a file encrypted with a passphrase that only the web server process knows.
B.The HSM encrypts the private key with a key derived from the server's TPM and stores the ciphertext on disk.
C.The HSM performs cryptographic operations internally so the private key never leaves the hardware boundary.
D.The HSM replicates the private key to a secure enclave in the server CPU, where it is used for TLS handshakes.
AnswerC

An HSM generates and stores private keys in tamper-resistant hardware and performs signing or decryption operations internally. The web server sends data to the HSM and receives the result, but the private key itself is never exposed to the host memory or file system. Even if the web server process is compromised, the attacker cannot extract the key from the HSM.

Why this answer

A hardware security module protects private keys by generating and using them inside tamper-resistant hardware. The key never enters the host's memory or file system, so a compromised web server process cannot read it. Encrypting keys on disk, using a TPM, or replicating keys to a CPU enclave still exposes the key material to the host at some point, which fails the stated requirement.

Exam trap

The trap here is confusing encryption of a key at rest with isolation of the key from the host, since a compromised process can read a decrypted key from memory.

97
MCQmedium

An application security team is reviewing code for vulnerabilities. They find that user input is directly concatenated into an SQL query without sanitization. This is an example of which OWASP Top 10 vulnerability?

A.Injection
B.Cross-Site Scripting (XSS)
C.Security Misconfiguration
D.Broken Access Control
AnswerA

Direct concatenation of unsanitised input into an SQL query is classic SQL injection, which falls under the OWASP Top 10 Injection category. The stem's defining constraint — untrusted input reaching an interpreter without sanitisation — is precisely the mechanism Injection describes, making it the accurate classification.

Why this answer

Concatenating unsanitized user input directly into an SQL query is the textbook definition of an Injection vulnerability (OWASP A03:2021). The untrusted input is interpreted as SQL code rather than data, allowing an attacker to alter query logic, bypass authentication, or exfiltrate the database. This is the classic SQL injection pattern.

Exam trap

The trap is confusing 'user input mishandled' with XSS — candidates must recognize that the interpreter here is the SQL database, not the browser, which makes it Injection.

How to eliminate wrong answers

Option B is wrong because XSS involves injecting client-side script into web pages rendered to other users, not manipulating database queries. Option C is wrong because Security Misconfiguration refers to insecure settings, defaults, or exposed services — not the handling of untrusted input in queries. Option D is wrong because Broken Access Control concerns users acting outside their intended permissions (e.g., IDOR, privilege escalation), not the injection of code into an interpreter.

98
MCQmedium

A company is deploying virtual machines (VMs) in a private cloud environment. To prevent VM escape attacks, which of the following is the most critical security control?

A.Using a separate management network for the hypervisor
B.Regularly patching the hypervisor software
C.Disabling unnecessary VM guest tools
D.Implementing a host-based firewall on each VM
AnswerB

VM escape exploits hypervisor or virtualisation-layer flaws to break isolation between guests and the host. Patching the hypervisor removes those known vulnerabilities, which is the control that directly prevents escape; guest patching and network controls do not address the shared layer.

Why this answer

Regularly patching the hypervisor software is the most critical control to prevent VM escape attacks because these attacks typically exploit vulnerabilities in the hypervisor itself. Keeping the hypervisor up to date ensures that known security flaws are remediated, reducing the attack surface. While other controls add defense in depth, patching directly addresses the root cause of most escape vulnerabilities.

Exam trap

The trap is selecting a control that provides isolation (like separate management network) or reduces attack surface (disabling tools) as the most critical, when the question asks for preventing VM escape, which is primarily achieved by patching the hypervisor.

How to eliminate wrong answers

Option A is wrong because a separate management network improves security by isolating management traffic, but it does not prevent VM escape if the hypervisor has an unpatched vulnerability. Option B is correct. Option C is wrong because disabling unnecessary VM guest tools reduces the attack surface within the guest, but VM escape exploits the hypervisor from the guest, so it is not the most critical control.

Option D is wrong because a host-based firewall on each VM controls network traffic to and from the VM, but it does not prevent a VM from exploiting a hypervisor vulnerability to escape.

99
MCQmedium

A security analyst is reviewing an OWASP Top 10 vulnerability report. Which vulnerability involves an attacker accessing unauthorized data by modifying URLs or API parameters?

A.Insecure Direct Object References (IDOR)
B.Cross-Site Scripting (XSS)
C.Injection
D.Security Misconfiguration
AnswerA

IDOR occurs when an application exposes a direct reference to an internal object, such as a record ID in a URL or API parameter, and fails to verify that the requester owns it. Manipulating that value returns another user's data.

Why this answer

Insecure Direct Object References (IDOR) occur when an application exposes internal object references without proper authorization checks, allowing attackers to manipulate parameters to access other objects.

100
MCQmedium

A company is concerned about VM sprawl in its data center. Which of the following is the most effective mitigation strategy?

A.Enable host-based firewalls on each VM
B.Implement a CMDB with lifecycle management policies
C.Apply patches to the hypervisor regularly
D.Use a centralized snapshot management system
AnswerB

A CMDB records every VM, owner and lifecycle state, and lifecycle policies enforce decommissioning of unused instances. This directly addresses sprawl by giving visibility and control over VM provisioning and retirement, satisfying the stem's mitigation requirement more effectively than periodic manual audits.

Why this answer

VM sprawl refers to unmanaged VMs accumulating. A Configuration Management Database (CMDB) with lifecycle management tracks VMs from creation to decommission. Hypervisor patching prevents escapes.

Snapshots are for recovery. Host-based firewalls protect individual VMs but do not manage sprawl.

101
Multi-Selecthard

A security engineer is hardening a Windows server that hosts a critical database. The server currently has many unnecessary services running. Which TWO of the following actions are most effective in reducing the attack surface of this server? (Choose two.)

Select 2 answers
A.Implement full disk encryption on the server's drives.
B.Apply the principle of least privilege to user accounts.
C.Install the latest antivirus software and keep it updated.
D.Enable a host-based firewall and close unused ports.
E.Disable unused Windows services and features.
AnswersD, E

Closing unused ports and enabling a host-based firewall restricts network access to only necessary services, directly reducing the attack surface. This prevents attackers from reaching potentially vulnerable services. It is a key hardening measure for servers.

Why this answer

Reducing attack surface involves eliminating unnecessary functionality and restricting access. Disabling unused services and features removes potential vulnerabilities, while closing unused ports and enabling a host-based firewall limits network exposure. Together, these actions significantly shrink the opportunities for an attacker to exploit the server.

Exam trap

The trap here is confusing general security best practices like antivirus or least privilege with specific attack surface reduction techniques.

← PreviousPage 2 of 2 · 101 questions total

Ready to test yourself?

Try a timed practice session using only Systems and Application Security questions.