Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CertNexus ITS-110 Exam - Topic 2 Question 75 Discussion

A hacker is able to access privileged information via an IoT portal by modifying a SQL parameter in a URL. Which of the following BEST describes the vulnerability that allows this type of attack?
D) Unhandled malformed URLs
A) Unvalidated redirect or forwarding
B) Insecure HTTP session management
C) Unsecure direct object references

CertNexus ITS-110 Exam - Topic 2 Question 75 Discussion

Actual exam question for CertNexus's ITS-110 exam
Question #: 75
Topic #: 2
[All ITS-110 Questions]

A hacker is able to access privileged information via an IoT portal by modifying a SQL parameter in a URL. Which of the following BEST describes the vulnerability that allows this type of attack?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Verda
12 hours ago
I agree, C fits. Direct access to objects is risky.
upvoted 0 times
...
Myong
6 days ago
I think it's C. Unsecure direct object references make sense here.
upvoted 0 times
...
Rueben
11 days ago
Wait, are we sure it's not about malformed URLs? That sounds plausible too.
upvoted 0 times
...
Amina
16 days ago
Totally agree with C, it's a classic vulnerability.
upvoted 0 times
...
Rusty
21 days ago
C seems right, but I'm surprised it can be that easy to exploit!
upvoted 0 times
...
Quentin
26 days ago
I think it's more about unvalidated redirects, though.
upvoted 0 times
...
Thea
1 month ago
This is definitely a case of unsecure direct object references.
upvoted 0 times
...
Alex
1 month ago
I think it's definitely about unvalidated redirects, but I might be mixing it up with something else I studied. This is tricky!
upvoted 0 times
...
Rikki
1 month ago
I feel like the answer has to do with session management, but I can't recall the specifics of how that connects to the URL parameter modification.
upvoted 0 times
...
Sheridan
2 months ago
I remember practicing a question about SQL injection, and it seems like that could fit here too. Is that what they mean by unhandled malformed URLs?
upvoted 0 times
...
Raylene
2 months ago
I think this might relate to unsecure direct object references, but I'm not entirely sure if that's the right term for SQL manipulation.
upvoted 0 times
...

Save Cancel