Free CompTIA Security+ SY0-701 Practice Question

A security analyst is reviewing the output of a vulnerability scan before importing it into the risk management register. The analyst notices an entry for CVE-2023-9999, which mentions that the software has unpatched SQL injection weaknesses. How should the analyst classify this vulnerability?

  • Insecure Deserialization

  • Cross-site Scripting (XSS)

  • Security Misconfiguration

  • Injection Flaws

This question's topic:
CompTIA Security+ SY0-701 / 
Security Operations
Your Score:

Check or uncheck an objective to set which questions you will receive.