Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-701 Exam - Topic 2 Question 85 Discussion

A security test performed on one of the applications shows that user input is not validated. Which security vulnerability is the application more susceptible to because of this lack of validation?
D) SQL injection
A) denial -of-service
B) cross-site request forgery
C) man-in-the-middle

Cisco 350-701 Exam - Topic 2 Question 85 Discussion

Actual exam question for Cisco's 350-701 exam
Question #: 85
Topic #: 2
[All 350-701 Questions]

A security test performed on one of the applications shows that user input is not validated. Which security vulnerability is the application more susceptible to because of this lack of validation?

Show Suggested Answer Hide Answer
Suggested Answer: D

An application that does not validate user input is particularly susceptible to SQL injection attacks. In an SQL injection attack, an attacker can insert or 'inject' a SQL query via the input data from the client to the application. Due to the lack of validation, the malicious SQL commands are executed by the database server, leading to unauthorized access or manipulation of the database.


Contribute your Thoughts:

0/2000 characters
Lennie
9 months ago
I’m surprised it’s not more obvious to everyone!
upvoted 0 times
...
Tabetha
9 months ago
100% agree, SQL injection is the big risk here.
upvoted 0 times
...
Edward
10 months ago
Wait, are we sure it’s not denial-of-service? Seems possible.
upvoted 0 times
...
Ilda
10 months ago
I thought it could be CSRF too, but SQL makes more sense.
upvoted 0 times
...
Zana
10 months ago
Definitely SQL injection, no validation means easy targets.
upvoted 0 times
...
Pearlene
10 months ago
Denial-of-service seems off to me; I think the lack of validation is more directly tied to SQL injection.
upvoted 0 times
...
Dick
11 months ago
I practiced a similar question about security vulnerabilities, and I think SQL injection is the most likely answer here.
upvoted 0 times
...
Starr
11 months ago
I'm not entirely sure, but I feel like cross-site scripting could also be a concern with unvalidated input.
upvoted 0 times
...
Pura
11 months ago
I remember we discussed input validation in class, and I think it relates to SQL injection vulnerabilities.
upvoted 0 times
...
Willie
11 months ago
I'm a bit confused on this question. I know it has something to do with input validation, but I'm not sure which specific vulnerability is the most likely. I'll have to review my notes on common web application vulnerabilities.
upvoted 0 times
...
Sylvia
11 months ago
Ah, I know this one! The lack of input validation makes the application susceptible to SQL injection. That's the security vulnerability I'd choose.
upvoted 0 times
...
Alica
11 months ago
Hmm, I'm not sure about this one. Could it also be vulnerable to cross-site request forgery or a denial-of-service attack? I'll have to think this through carefully.
upvoted 0 times
...
Thora
11 months ago
This one seems pretty straightforward. If the application doesn't validate user input, it's likely vulnerable to SQL injection.
upvoted 0 times
...
Tamar
11 months ago
Okay, I've got this. If the application doesn't validate user input, that means it's open to SQL injection attacks. That's the security vulnerability I'll select for this question.
upvoted 0 times
...
Yolando
11 months ago
I'm feeling a little lost on this one. Can someone walk me through the process?
upvoted 0 times
...
Val
11 months ago
I'm leaning towards diversification because they're teaming up with another company, but I might be confusing it with other cases we've studied.
upvoted 0 times
...
Bernardine
11 months ago
I'm a bit confused here. Shouldn't we get a compilation error since the Vehicle class doesn't implement Comparable? How is the TreeSet supposed to sort the objects without a defined ordering?
upvoted 0 times
...
Earleen
11 months ago
Watch out for tricky wording. 'Objective' means something you can actually measure or observe, not just what the patient tells you. That points to vital signs.
upvoted 0 times
...
Ardella
11 months ago
I feel like "GOLF" was mentioned, but I can't quite remember its relevance to this topic. Maybe I should rethink my answer.
upvoted 0 times
...
Kris
2 years ago
True, cross-site request forgery is definitely a concern. But SQL injection can lead to more damaging consequences.
upvoted 0 times
...
Glen
2 years ago
But what about cross-site request forgery? That could also be a major threat.
upvoted 0 times
...
Tran
2 years ago
I agree with Without input validation, SQL injection attacks can easily exploit vulnerabilities.
upvoted 0 times
...
Kris
2 years ago
I think the application is more susceptible to SQL injection.
upvoted 0 times
...
Carlene
2 years ago
Exactly, SQL injection could be a big threat.
upvoted 0 times
...
Glen
2 years ago
It could be susceptible to things like SQL injection.
upvoted 0 times
...
Zoila
2 years ago
That's a major vulnerability. What could it lead to?
upvoted 0 times
Carissa
2 years ago
Data sent between the user and server could be intercepted.
upvoted 0 times
...
Sarina
2 years ago
C) man-in-the-middle
upvoted 0 times
...
Martina
2 years ago
The application could become unresponsive to legitimate users.
upvoted 0 times
...
Adria
2 years ago
A) denial-of-service
upvoted 0 times
...
Gretchen
2 years ago
Attackers could manipulate user actions without their consent.
upvoted 0 times
...
Elly
2 years ago
B) cross-site request forgery
upvoted 0 times
...
Amos
2 years ago
It could lead to unauthorized access to the database.
upvoted 0 times
...
Herman
2 years ago
D) SQL injection
upvoted 0 times
...
...
Carlene
2 years ago
The security test found that user input isn't validated.
upvoted 0 times
...

Save Cancel