adplus-dvertising
frame-decoration

Question

Monica discovers that an attacker posted a message attacking users who visit a web forum that she manages. Which one of the following attack types is most likely to have occurred?

a.

SQL injection

b.

Malware injection

c.

LDAP injection

d.

Cross-site scripting

Answer: (d).Cross-site scripting Explanation:In a cross-site scripting (XSS) attack, an attacker embeds scripting commands on a website that will later be executed by an unsuspecting visitor accessing the site. The idea is to trick a user visiting a trusted site into executing malicious code placed there by an untrusted third party.

Engage with the Community - Add Your Comment

Confused About the Answer? Ask for Details Here.

Know the Explanation? Add it Here.

Q. Monica discovers that an attacker posted a message attacking users who visit a web forum that she manages. Which one of the following attack types is most likely to have occurred?

Similar Questions

Discover Related MCQs

Q. Which one of the following terms is not typically used to describe the connection of physical devices to a network?

Q. In what type of attack does the attacker seek to gain access to resources assigned to a different virtual machine?

Q. What software component is responsible for enforcing the separation of guest systems in a virtualized infrastructure?

Q. Which one of the following conditions would not result in a certificate warning during a vulnerability scan of a web server?

Q. Betty is selecting a transport encryption protocol for use in a new public website she is creating. Which protocol would be the best choice?

Q. Which one of the following protocols should never be used on a public network?

Q. The Dirty COW attack is an example of what type of vulnerability?

Q. In what type of attack does the attacker place more information in a memory location than is allocated for that use?

Q. Which one of the following operating systems should be avoided on production networks?

Q. Which one of the following is not a common source of information that may be correlated with vulnerability scan results?

Q. Tara recently analyzed the results of a vulnerability scan report and found that a vulnerability reported by the scanner did not exist because the system was actually patched as specified. What type of error occurred?

Q. Kevin recently identified a new security vulnerability and computed its CVSS base score as 6.5. Which risk category would this vulnerability fall into?

Q. Which one of the following metrics is not included in the calculation of the CVSS exploitability score?

Q. What is the most recent version of CVSS that is currently available?

Q. Which one of the following values for the confidentiality, integrity, or availability CVSS metric would indicate the potential for total compromise of a system?

Q. Which one of the following values for the CVSS attack complexity metric would indicate that the specified attack is simplest to exploit?

Q. Which one of the CVSS metrics would contain information about the type of user account an attacker must use to execute an attack?

Q. Tom is reviewing a vulnerability scan report and finds that one of the servers on his network suffers from an internal IP address disclosure vulnerability. What protocol is likely in use on this network that resulted in this vulnerability?

Q. What is a suggested solution often provided in vulnerability scan reports?

Q. What does the CVSS base score consider regarding the impact of a vulnerability?