Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

EC-Council 312-49 Exam - Topic 15 Question 93 Discussion

When Investigating a system, the forensics analyst discovers that malicious scripts were Injected Into benign and trusted websites. The attacker used a web application to send malicious code. In the form of a browser side script, to a different end-user. What attack was performed here?
C) Cross-site scripting attack
A) Brute-force attack
B) Cookie poisoning attack
D) SQL injection attack

EC-Council 312-49 Exam - Topic 15 Question 93 Discussion

Actual exam question for EC-Council's 312-49 exam
Question #: 93
Topic #: 15
[All 312-49 Questions]

When Investigating a system, the forensics analyst discovers that malicious scripts were Injected Into benign and trusted websites. The attacker used a web application to send malicious code. In the form of a browser side script, to a different end-user. What attack was performed here?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Dorothy
25 days ago
Brute-force attack doesn't apply here. XSS is the right choice.
upvoted 0 times
...
Brice
1 month ago
Cookie poisoning doesn't match this scenario. It's XSS for sure.
upvoted 0 times
...
Tom
1 month ago
I was torn between XSS and SQL injection, but XSS fits better.
upvoted 0 times
...
Soledad
1 month ago
I agree. The way they inject code is typical of XSS.
upvoted 0 times
...
Veda
2 months ago
Yeah, definitely. Malicious scripts in trusted sites? Classic XSS.
upvoted 0 times
...
Lamar
2 months ago
I think it's a Cross-site scripting attack. Makes sense.
upvoted 0 times
...
Gail
2 months ago
Sounds too easy, but I guess it fits the description.
upvoted 0 times
...
Kiley
2 months ago
Yeah, C is the right answer. No doubt about it!
upvoted 0 times
...
Josephine
2 months ago
Wait, are we sure it's not SQL injection?
upvoted 0 times
...
Brigette
2 months ago
I think it's C too, makes the most sense.
upvoted 0 times
...
Katlyn
3 months ago
Definitely a Cross-site scripting attack!
upvoted 0 times
...
Margarita
3 months ago
Sounds fishy, I have my doubts about this whole scenario.
upvoted 0 times
...
Carrol
3 months ago
Wait, are we sure it's not cookie poisoning?
upvoted 0 times
...
Jettie
3 months ago
Agreed, it's C for sure.
upvoted 0 times
...
Starr
5 months ago
I think it's more of a SQL injection attack.
upvoted 0 times
...
Dianne
5 months ago
Definitely a Cross-site scripting attack!
upvoted 0 times
...
Lucille
5 months ago
I’m a bit confused. Isn’t SQL injection more about databases? This seems more like a web-based attack.
upvoted 0 times
...
Suzi
5 months ago
I practiced a similar question, and I believe the answer is C) Cross-site scripting. It fits the description of the attack.
upvoted 0 times
...
Glynda
6 months ago
I'm not entirely sure, but I remember something about cookie poisoning. Could that be related here?
upvoted 0 times
...
Tesha
6 months ago
I think this sounds like a Cross-site scripting attack, right? It involves injecting scripts into trusted sites.
upvoted 0 times
...

Save Cancel