Threats & AttacksPregunta 8 de 100
Which attack injects malicious database commands through unvalidated user input fields?
a.Cross-site scripting
b.SQL injection
c.Directory traversal
d.Session hijacking
Explicación
SQL injection inserts crafted database statements through input that the application fails to sanitize. It can expose, modify, or delete data. Parameterized queries and input validation are the primary defenses.
Practica las 100 preguntas gratis — sin registro.
Preguntas relacionadas de este tema
- An attacker overwhelms a web server with traffic from thousands of compromised devices, making it unavailable. What is this called?
- Which type of threat actor is typically well-funded, highly skilled, and motivated by espionage on behalf of a government?
- A disgruntled employee copies confidential designs to a USB drive before resigning. This is an example of what threat?
- An attacker leaves infected USB drives in a company parking lot hoping employees will plug them in. This technique is known as:
- Which malware disguises itself as legitimate software but performs malicious actions once installed?
- A malicious program spreads across a network automatically without any user interaction. What is it?
Última revisión: · proceso editorial
Sen Lin, Fundador de PrepPass · Verificado con CompTIA Security+ (SY0-701) · Cómo revisamos