exam questions

Exam CCSP All Questions

View all questions & answers for the CCSP exam

Exam CCSP topic 1 question 242 discussion

Actual exam question from ISC's CCSP
Question #: 242
Topic #: 1
[All CCSP Questions]

Which of the following threat types involves the sending of commands or arbitrary data through input fields in an application in an attempt to get that code executed as part of normal processing?

  • A. Cross-site scripting
  • B. Missing function-level access control
  • C. Injection
  • D. Cross-site forgery
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MaciekMT
1 month, 4 weeks ago
Selected Answer: C
Injection attacks involve sending malicious commands or arbitrary data through input fields, tricking the application into executing unintended commands as part of its normal processing. This contrasts with Cross-site scripting, which targets client-side code execution, and cross-site request forgery, which leverages authenticated sessions to force unwanted actions. Missing function-level access control is about inadequate permission checks rather than injecting code.
upvoted 1 times
...
zxccvbnm
8 months, 1 week ago
Selected Answer: C
C. Injection
upvoted 2 times
...
Pravinkarthik
9 months ago
Selected Answer: C
C. Injection
upvoted 1 times
...
akg001
11 months ago
Selected Answer: D
D. Possession, custody, control
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago