ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 435 - SY0-601 discussion

Report
Export

A security engineer obtained the following output from a threat intelligence source that recently performed an attack on the company's server:

Which of the following best describes this kind of attack?

A.
Directory traversal
Answers
A.
Directory traversal
B.
SQL injection
Answers
B.
SQL injection
C.
API
Answers
C.
API
D.
Request forgery
Answers
D.
Request forgery
Suggested answer: A

Explanation:

Directory traversal is a type of web application attack that involves exploiting a vulnerability in the web server or application to access files or directories that are outside the intended scope or root directory. It can allow an attacker to read, modify, or execute files on the target system by using special characters such as .../ or %2e%2e/ to manipulate the path or URL. In this case, the attacker used .../ to access the /etc/passwd file, which contains user account information on Linux systems.

asked 02/10/2024
Steven Owens
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first