Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisEasy
A security analyst is investigating a potential compromise involving a web server. The analyst discovers a large number of HTTP GET requests to a non-existent file path, `/.env`, from various external IP addresses. These requests are occurring rapidly and originate from different geographical locations. What type of attack is most likely underway?
- AVulnerability Scanning
- BDirectory Traversal
- CCross-Site Request Forgery (CSRF)
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: A. Vulnerability Scanning
Rapid, widespread requests for common sensitive files (like '.env', which often contains environment variables and credentials) to non-existent paths from various external IPs are characteristic of automated vulnerability scanning, where attackers probe for misconfigurations or exposed files.
Why the other options are wrong
- B. Directory traversal attempts to access files outside the web root (e.g., `../etc/passwd`), not typically a direct request for a specific sensitive file like '.env' in the root.
- C. CSRF exploits a user's authenticated session to trick them into performing unwanted actions, which doesn't involve direct requests for sensitive files from external IPs.
- D. SQL injection targets database queries, usually via parameters in legitimate-looking requests, not direct requests for specific files like '.env'.
Vulnerability Scanning
The automated process of identifying security weaknesses in systems, applications, or networks by systematically probing for known vulnerabilities, misconfigurations, or exposed sensitive information.
- Often involves automated tools
- Probes for common weaknesses
- Can precede more targeted attacks
Memory trick: Web Attacks: Scan, Inject, Traverse, Script.