ExamGecko
Question list
Search
Search

Related questions

Question 163 - CISA discussion

Report
Export

An IS auditor discovers that validation controls m a web application have been moved from the server side into the browser to boost performance This would MOST likely increase the risk of a successful attack by.

A.
phishing.
Answers
A.
phishing.
B.
denial of service (DoS)
Answers
B.
denial of service (DoS)
C.
structured query language (SQL) injection
Answers
C.
structured query language (SQL) injection
D.
buffer overflow
Answers
D.
buffer overflow
Suggested answer: C

Explanation:

Moving validation controls from the server side into the browser would most likely increase the risk of a successful attack by structured query language (SQL) injection. SQL injection is a technique that exploits a security vulnerability in an application's database layer by inserting malicious SQL statements into user input fields. Validation controls are used to check and filter user input before sending it to the database. If these controls are moved to the browser, they can be easily bypassed or modified by an attacker, who can then execute arbitrary SQL commands on the database.Reference:CISA Review Manual, 27th Edition, page 361

asked 18/09/2024
brandon millette
50 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first