Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsEasy
Which of the following attack vectors primarily exploits vulnerabilities in web applications to inject malicious code into legitimate websites, which is then executed by unsuspecting users' browsers?
- ASQL Injection
- BCross-Site Scripting (XSS)
- CDistributed Denial of Service (DDoS)
- DPhishing
Show answer & explanationAnswer & explanation
Correct answer: B. Cross-Site Scripting (XSS)
Cross-Site Scripting (XSS) specifically involves injecting client-side scripts into web pages viewed by other users, allowing attackers to bypass access controls and steal data or perform actions on behalf of the user. This directly matches the scenario described.
Why the other options are wrong
- A. SQL Injection attacks target databases by inserting malicious SQL queries through web application input fields, primarily affecting database integrity and access, not browser-side script execution.
- C. DDoS attacks aim to make a service unavailable by overwhelming it with traffic, rather than injecting malicious code.
- D. Phishing is a social engineering attack that tricks users into divulging sensitive information, not injecting code into websites.
Cross-Site Scripting (XSS)
A type of web security vulnerability typically found in web applications. XSS enables attackers to inject client-side scripts into web pages viewed by other users.
- Injects malicious script into a legitimate website.
- Script executes in the victim's browser.
- Can steal cookies, session tokens, or deface websites.
Memory trick: Web attacks can be tricky; XSS injects code, SQL injects data, DDoS blocks access.