Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsHard

A security team is conducting a penetration test on a new web application. During the test, they discover that by manipulating URL parameters, they can bypass authentication and access administrative functions. This type of vulnerability, where an attacker can elevate their privileges without proper authorization, is known as:

  1. ABroken Access Control
  2. BDenial of Service (DoS)
  3. CCross-Site Scripting (XSS)
  4. DCross-Site Request Forgery (CSRF)
Show answer & explanation

Correct answer: A. Broken Access Control

Bypassing authentication and accessing administrative functions by manipulating URL parameters is a classic example of Broken Access Control, where an application fails to properly enforce restrictions on what authenticated users are allowed to do.

Why the other options are wrong

  • B. DoS attacks aim to make a service unavailable, not to gain unauthorized access.
  • C. XSS involves injecting malicious scripts into content viewed by other users.
  • D. CSRF tricks a user into performing unintended actions on a web application.

Broken Access Control

A common web application vulnerability where restrictions on what authenticated users are allowed to do are not properly enforced, leading to unauthorized access to functionality or data.

  • Users can access unauthorized resources/functions.
  • Often due to incorrect permission checks.
  • A top vulnerability in OWASP Top 10.

Memory trick: Access control can be broken, not just scripts or requests.

More Cybersecurity Fundamentals questions