CompTIA Security+ SY0-701 Practice Question
An attacker can compromise the security of a web application by manipulating input to navigate to and manipulate files located in the server's filesystem that are not intended to be accessible.
False
True
An attacker can compromise the security of a web application by manipulating input to navigate to and manipulate files located in the server's filesystem that are not intended to be accessible.
False
True
A directory traversal attack, also known as path or file traversal, involves manipulating variables that reference files with dot-dot-slash (../) sequences and similar techniques, to access arbitrary files and directories on the application server filesystem, including application source code, configuration, and critical system files. This attack occurs when user input is not properly sanitized, allowing attackers to traverse the directory tree. Therefore, the correct answer is that the statement is true, as this kind of input manipulation is indeed a method used in directory traversal attacks. Incorrect answers might seem plausible if they relate to information disclosure only or suggest that the attack cannot manipulate files, but these are incorrect because directory traversal can potentially allow both reading and writing to files outside of the intended directory structure.
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
All Information Technology Package plans include the following perks and exams.
Our pricing is simple. Full access to all certifications and exams in each package, for one price.
As many practice tests for as many topics as you want.
Use study mode non-stop, no limits.
Access to our AI assistant, Bash, trained to help you pass your exam.
Track your scores over time in study mode and report cards.
See how you improve over time, and where you need to focus.
Unlimited access to all performance questions and be prepared for the real thing.
All Information Technology Package plans include unlimited access to the following study materials.
Create an account or sign in to access our study materials.