Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsEasy

Which of the following common attack vectors exploits vulnerabilities in web applications by injecting malicious scripts into content that is then delivered to other users?

  1. ADenial of Service (DoS)
  2. BCross-Site Scripting (XSS)
  3. CBuffer Overflow
  4. DSQL Injection
Show answer & explanation

Correct answer: B. Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS) is a web security vulnerability that enables attackers to inject client-side scripts into web pages viewed by other users. This allows them to bypass access controls and perform actions on behalf of the victim.

Why the other options are wrong

  • A. DoS aims to make a service unavailable, not inject scripts into web content.
  • C. Buffer Overflow exploits memory management errors, not web application script injection.
  • D. SQL Injection targets database queries, not client-side script injection.

Cross-Site Scripting (XSS)

A type of security vulnerability typically found in web applications that enables attackers to inject client-side scripts into web pages viewed by other users.

  • Targets web applications.
  • Involves injecting client-side scripts (e.g., JavaScript).
  • Affects other users viewing the compromised content.
  • Can lead to session hijacking, defacement, or malware delivery.

Memory trick: Web attacks target the browser and server, like XSS injecting scripts to cross sites.

More Security Concepts questions