ExamGecko
Question list
Search
Search

Related questions











Question 691 - CISA discussion

Report
Export

Which type of attack targets security vulnerabilities in web applications to gain access to data sets?

A.
Denial of service (DOS)
Answers
A.
Denial of service (DOS)
B.
SQL injection
Answers
B.
SQL injection
C.
Phishing attacks
Answers
C.
Phishing attacks
D.
Rootkits
Answers
D.
Rootkits
Suggested answer: B

Explanation:

A SQL injection attack is a type of attack that targets security vulnerabilities in web applications to gain access to data sets. A SQL injection attack exploits a flaw in the web application code that allows an attacker to inject malicious SQL statements into the input fields or parameters of the web application. These SQL statements can then execute on the underlying database server and manipulate or retrieve sensitive data from the database. A SQL injection attack can result in data theft, data corruption, unauthorized access, denial of service or even complete takeover of the database server. A denial of service (DOS) attack is a type of attack that aims to disrupt the availability or functionality of a web application or a network service by overwhelming it with excessive requests or traffic. A phishing attack is a type of attack that uses deceptive emails or websites to trick users into revealing their personal or financial information or credentials. A rootkit is a type of malware that hides itself from detection and grants unauthorized access or control over a compromised system.Reference:IS Audit and Assurance Tools and Techniques,CISA Certification | Certified Information Systems Auditor | ISACA

asked 18/09/2024
Tim Baas
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first