Free CompTIA CySA+ CS0-003 Practice Question

A web application security auditor notices that a company’s web application displays search results directly in the web page without sanitizing or encoding the user's input. The auditor suspects that this behavior could allow an attacker to execute a type of vulnerability related to injecting malicious scripts. What type of vulnerability is likely to be present in this scenario?

  • Persistent cross-site scripting

  • SQL injection

  • Reflected cross-site scripting

  • Cross-site request forgery (CSRF)

This question's topic:
CompTIA CySA+ CS0-003 / 
Vulnerability Management
Your Score:

Check or uncheck an objective to set which questions you will receive.