Which of the following is a type of attack that uses malicious code to exploit vulnerabilities in web applications? MCQ with Answer and Explanation

Which of the following is a type of attack that uses malicious code to exploit vulnerabilities in web applications?
A. Phishing
B. Cross-site scripting (XSS)
C. Denial-of-service
D. Man-in-the-middle
Answer: Option B
Solution (By JKSSB Mock Tests)
Cross-site scripting (XSS) is a type of attack where malicious scripts are injected into web applications, exploiting vulnerabilities to steal data or hijack sessions.

Discuss this Question (0)

No comments yet. Be the first to start the discussion!

Practice More Cyber Security Questions

Question #1
What is the purpose of a vulnerability management program?
A. To install new software
B. To increase system performance
C. To identify, prioritize, and remediate vulnerabilities
D. To manage user accounts

Correct Answer: Option C


Explanation:
A vulnerability management program systematically identifies, prioritizes, and remediates security vulnerabilities to reduce the risk of exploitation.

This question belongs to: Computer Cyber Security
Question #2
What type of attack relies on social engineering to drop malicious flash drives in a company parking lot, hoping an employee will plug one into a corporate workstation out of curiosity?
A. Whaling Attack
B. Pharming Exploit
C. Smishing Attempt
D. Baiting

Correct Answer: Option D


Explanation:
Baiting uses the promise of an item or curiosity (like a misplaced USB drive with an intriguing label) to entice victims into compromising their own system security.

This question belongs to: Computer Cyber Security
Question #3
What security mechanism acts as an analytical perimeter boundary, monitoring and filtering incoming and outgoing network traffic based on an organization's pre-established rule policies?
A. Firewall
B. Antivirus Scan Engine
C. Digital Certificate Registry
D. Intrusion Detection Honeypot

Correct Answer: Option A


Explanation:
A firewall filters data packets shifting across network interfaces, blocking or permitting connections according to specific access control security metrics.

This question belongs to: Computer Cyber Security