Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsEasy

A large e-commerce company is preparing to launch a new version of its online store. Before release, the security team conducts a comprehensive audit to identify and remediate potential weaknesses. During this audit, they discover that the application uses a default administrative password that was not changed during installation. Which common security vulnerability does this represent?

  1. ACross-Site Scripting (XSS)
  2. BBroken Authentication
  3. CSecurity Misconfiguration
  4. DInjection Flaw
Show answer & explanation

Correct answer: C. Security Misconfiguration

Security misconfiguration refers to flaws in the way systems or applications are set up, including leaving default credentials, unnecessary services enabled, or incorrect permissions. Failing to change a default administrative password is a classic example of this vulnerability.

Why the other options are wrong

  • A. XSS involves injecting client-side scripts into web pages, which is unrelated to default administrative passwords.
  • B. Broken authentication relates to flaws in session management or credential handling, not directly to default installation settings.
  • D. Injection flaws involve malicious input being processed by an interpreter, not default passwords.

Security Misconfiguration

A common security vulnerability that arises from improper setup or maintenance of a system, application, or network component. This can include using default credentials, enabling unnecessary services, or incorrectly configuring permissions.

  • Often results from oversight during installation or deployment.
  • Can include default passwords, open ports, or verbose error messages.
  • Is a preventable vulnerability through secure configuration practices.

Memory trick: Misconfiguration is like leaving the back door open after moving in.

More Security Concepts questions