Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsEasy
A large e-commerce company is preparing to launch a new version of its online store. Before release, the security team conducts a comprehensive audit to identify and remediate potential weaknesses. During this audit, they discover that the application uses a default administrative password that was not changed during installation. Which common security vulnerability does this represent?
- ACross-Site Scripting (XSS)
- BBroken Authentication
- CSecurity Misconfiguration
- DInjection Flaw
Show answer & explanationAnswer & explanation
Correct answer: C. Security Misconfiguration
Security misconfiguration refers to flaws in the way systems or applications are set up, including leaving default credentials, unnecessary services enabled, or incorrect permissions. Failing to change a default administrative password is a classic example of this vulnerability.
Why the other options are wrong
- A. XSS involves injecting client-side scripts into web pages, which is unrelated to default administrative passwords.
- B. Broken authentication relates to flaws in session management or credential handling, not directly to default installation settings.
- D. Injection flaws involve malicious input being processed by an interpreter, not default passwords.
Security Misconfiguration
A common security vulnerability that arises from improper setup or maintenance of a system, application, or network component. This can include using default credentials, enabling unnecessary services, or incorrectly configuring permissions.
- Often results from oversight during installation or deployment.
- Can include default passwords, open ports, or verbose error messages.
- Is a preventable vulnerability through secure configuration practices.
Memory trick: Misconfiguration is like leaving the back door open after moving in.