โ† All Certified Ethical Hacker Flashcard Decks

Ethical Hacker Security Flashcards

7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Ethical Hacker Security flashcards as text
  1. Which web vulnerability allows an attacker to inject malicious SQL into a query?

    Answer: SQL injection

    SQL injection inserts malicious SQL into input fields to manipulate the backend database.

  2. Stored cross-site scripting (XSS) is dangerous primarily because:

    Answer: The payload persists and affects many users

    Stored XSS saves the malicious script on the server, executing for every user who views the page.

  3. Which attack forces an authenticated user to execute unwanted actions on a web app?

    Answer: CSRF

    Cross-Site Request Forgery tricks a logged-in user's browser into sending forged requests.

  4. What is the best defense against SQL injection?

    Answer: Parameterized queries

    Parameterized (prepared) statements separate code from data, preventing injection.

  5. Which tool is a web server vulnerability scanner that checks for outdated software and misconfigurations?

    Answer: Nikto

    Nikto scans web servers for known vulnerabilities, dangerous files, and outdated versions.

  6. An attacker manipulates a URL parameter to access another user's record without authorization. This is:

    Answer: Insecure Direct Object Reference (IDOR)

    IDOR occurs when an app exposes references to internal objects without proper access checks.

  7. Which header helps mitigate cross-site scripting by restricting script sources?

    Answer: Content-Security-Policy

    Content-Security-Policy restricts which sources can load scripts, limiting XSS impact.