Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsEasy
Which of the following common attack vectors exploits vulnerabilities in web applications by injecting malicious scripts into content that is then delivered to other users?
- ADenial of Service (DoS)
- BCross-Site Scripting (XSS)
- CBuffer Overflow
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: B. Cross-Site Scripting (XSS)
Cross-Site Scripting (XSS) is a web security vulnerability that enables attackers to inject client-side scripts into web pages viewed by other users. This allows them to bypass access controls and perform actions on behalf of the victim.
Why the other options are wrong
- A. DoS aims to make a service unavailable, not inject scripts into web content.
- C. Buffer Overflow exploits memory management errors, not web application script injection.
- D. SQL Injection targets database queries, not client-side script injection.
Cross-Site Scripting (XSS)
A type of security vulnerability typically found in web applications that enables attackers to inject client-side scripts into web pages viewed by other users.
- Targets web applications.
- Involves injecting client-side scripts (e.g., JavaScript).
- Affects other users viewing the compromised content.
- Can lead to session hijacking, defacement, or malware delivery.
Memory trick: Web attacks target the browser and server, like XSS injecting scripts to cross sites.