Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil ECSS Exam - Topic 9 Question 120 Discussion

Melanie, a professional hacker, is attempting to break into a target network through an application server. In this process, she identified a logic flaw in the target web application that provided visibility into the source code. She exploited this vulnerability to launch further attacks on the target web application.Which of the web application vulnerabilities was identified by Melanie in the above scenario?
B) Security misconfiguration
A) Insecure deserialization
C) Command injection
D) Broken authentication

Eccouncil ECSS Exam - Topic 9 Question 120 Discussion

Actual exam question for Eccouncil's ECSS exam
Question #: 120
Topic #: 9
[All ECSS Questions]

Melanie, a professional hacker, is attempting to break into a target network through an application server. In this process, she identified a logic flaw in the target web application that provided visibility into the source code. She exploited this vulnerability to launch further attacks on the target web application.

Which of the web application vulnerabilities was identified by Melanie in the above scenario?

Show Suggested Answer Hide Answer
Suggested Answer: B

Melanie discovered alogic flawin the target web application that allowed her to view thesource code. This flaw indicates asecurity misconfiguration, which can lead to further attacks.Security misconfigurations occur when an application or system is not properly configured, leaving it vulnerable to exploitation.Reference: EC-Council Certified Security Specialist (E|CSS) documents and study guide12.


Contribute your Thoughts:

0/2000 characters
Tina
2 days ago
Sounds like a logic flaw, but I’m not sure if it fits neatly into any of these options.
upvoted 0 times
...
Timothy
7 days ago
I disagree, it’s not broken authentication. That’s not what happened here.
upvoted 0 times
...
Harrison
12 days ago
Wait, how did she see the source code? That's surprising!
upvoted 0 times
...
Alisha
18 days ago
I think it's A) Insecure deserialization. Seems like a classic flaw.
upvoted 0 times
...
Chantay
23 days ago
Definitely B) Security misconfiguration. That makes the most sense.
upvoted 0 times
...
Lelia
28 days ago
Not sure about that, could be command injection too.
upvoted 0 times
...
Salley
1 month ago
Definitely broken authentication, no doubt about it.
upvoted 0 times
...
Evangelina
1 month ago
Wait, she saw the source code? That's wild!
upvoted 0 times
...
Lizbeth
1 month ago
I think it’s more about security misconfiguration.
upvoted 0 times
...
Glory
2 months ago
Sounds like a classic case of insecure deserialization.
upvoted 0 times
...
Latricia
2 months ago
Broken authentication seems off here; I feel like the focus is more on the logic flaw and code exposure. Could it really be security misconfiguration?
upvoted 0 times
...
Andree
2 months ago
Command injection sounds familiar, but I don't recall it being about source code visibility. This one's tricky!
upvoted 0 times
...
Carey
2 months ago
I remember a practice question about security misconfiguration that involved exposing source code. That could be it, right?
upvoted 0 times
...
Carri
4 months ago
I think this might be related to insecure deserialization, but I'm not entirely sure how that connects to the source code visibility.
upvoted 0 times
...

Save Cancel