Attacks and Exploits
An application concatenates untrusted user input directly into a database query, allowing an attacker to alter the query's logic. Which vulnerability class is this?
- ADenial of service
- BCross-site scripting
- CSQL injectionCorrect
- DPhysical tailgating
Why: SQL injection occurs when untrusted input is placed into a database query without proper parameterization, letting an attacker change the query's logic. The defense is to use parameterized queries and input validation. Cross-site scripting targets the browser, not the database.
Reconnaissance and Enumeration
A tester gathers information about a target organization from public sources such as social media, job postings, and DNS records without sending any packets to the target's systems. Which activity is this?
- APrivilege escalation
- BActive scanning
- CExploitation
- DPassive reconnaissance (OSINT)Correct
Why: Passive reconnaissance, including open-source intelligence (OSINT), collects information from publicly available sources without directly interacting with the target's systems, making it stealthy. Active scanning sends traffic to the target and is therefore detectable, unlike passive collection.