Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityMedium

A security analyst is investigating a suspected data breach where an attacker exfiltrated sensitive customer information. The post-incident analysis reveals that the attacker gained access through a web application vulnerability that allowed them to execute arbitrary commands on the underlying server. Which type of attack did the attacker most likely use to achieve this?

  1. ACross-Site Scripting (XSS)
  2. BDenial of Service (DoS)
  3. CCommand Injection
  4. DCross-Site Request Forgery (CSRF)
Show answer & explanation

Correct answer: C. Command Injection

Command injection occurs when an attacker can execute arbitrary commands on the host operating system through a vulnerable application. This directly matches the scenario where an attacker used a web application vulnerability to 'execute arbitrary commands on the underlying server' to exfiltrate data.

Why the other options are wrong

  • A. XSS allows attackers to inject malicious client-side scripts into web pages, affecting users, not directly executing commands on the server.
  • B. DoS attacks aim to make a service unavailable, not to gain command execution for data exfiltration.
  • D. CSRF forces an end-user to execute unwanted actions on a web application in which they're currently authenticated, not server command execution.

Command Injection

A web application vulnerability that allows an attacker to execute arbitrary operating system commands on the server hosting the application.

  • Occurs when an application passes user-supplied data to a system shell without proper sanitization.
  • Can lead to full system compromise and data exfiltration.
  • Mitigated by strict input validation and avoiding system calls with user input.

Memory trick: Command Injection: The attacker's 'remote control' for your server.

More Network Security questions