Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsHard
A software development team is performing a code review and discovers a vulnerability where the application accepts user input without proper validation, potentially allowing malicious scripts to be executed in a user's browser. Which type of attack does this vulnerability enable?
- ACross-Site Request Forgery (CSRF)
- BDirectory Traversal
- CCross-Site Scripting (XSS)
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: C. Cross-Site Scripting (XSS)
Cross-Site Scripting (XSS) attacks occur when an attacker injects malicious client-side scripts into web pages viewed by other users, typically due to improper input validation.
Why the other options are wrong
- A. CSRF forces an end user to execute unwanted actions on a web application where they're currently authenticated.
- B. Directory Traversal allows attackers to access files and directories stored outside the web root folder.
- D. SQL Injection targets databases by injecting malicious SQL code.
Cross-Site Scripting (XSS)
Cross-Site Scripting (XSS) is a type of security vulnerability typically found in web applications. XSS attacks enable attackers to inject client-side scripts into web pages viewed by other users.
- Relies on improper input validation by the web application.
- Malicious scripts execute in the victim's browser.
- Can steal session cookies, deface websites, or redirect users.
Memory trick: Web apps can be attacked by injecting Code, Forging requests, or Traversing paths.