Ethical Hacker Security Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Ethical Hacker Security flashcards as text
Which web vulnerability allows an attacker to inject malicious SQL into a query?
Answer: SQL injection
SQL injection inserts malicious SQL into input fields to manipulate the backend database.
Stored cross-site scripting (XSS) is dangerous primarily because:
Answer: The payload persists and affects many users
Stored XSS saves the malicious script on the server, executing for every user who views the page.
Which attack forces an authenticated user to execute unwanted actions on a web app?
Answer: CSRF
Cross-Site Request Forgery tricks a logged-in user's browser into sending forged requests.
What is the best defense against SQL injection?
Answer: Parameterized queries
Parameterized (prepared) statements separate code from data, preventing injection.
Which tool is a web server vulnerability scanner that checks for outdated software and misconfigurations?
Answer: Nikto
Nikto scans web servers for known vulnerabilities, dangerous files, and outdated versions.
An attacker manipulates a URL parameter to access another user's record without authorization. This is:
Answer: Insecure Direct Object Reference (IDOR)
IDOR occurs when an app exposes references to internal objects without proper access checks.
Which header helps mitigate cross-site scripting by restricting script sources?
Answer: Content-Security-Policy
Content-Security-Policy restricts which sources can load scripts, limiting XSS impact.