CompTIA Security+ SY0-701 Practice Question
An attacker can compromise the security of a web application by manipulating input to navigate to and manipulate files located in the server's filesystem that are not intended to be accessible.
True
False
An attacker can compromise the security of a web application by manipulating input to navigate to and manipulate files located in the server's filesystem that are not intended to be accessible.
True
False
A directory traversal attack, also known as path or file traversal, involves manipulating variables that reference files with dot-dot-slash (../) sequences and similar techniques, to access arbitrary files and directories on the application server filesystem, including application source code, configuration, and critical system files. This attack occurs when user input is not properly sanitized, allowing attackers to traverse the directory tree. Therefore, the correct answer is that the statement is true, as this kind of input manipulation is indeed a method used in directory traversal attacks. Incorrect answers might seem plausible if they relate to information disclosure only or suggest that the attack cannot manipulate files, but these are incorrect because directory traversal can potentially allow both reading and writing to files outside of the intended directory structure.
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Join premium for unlimited access and more features
All plans include the following perks.
Our pricing is simple. Full access to all certifications and exams, for one price.
As many practice tests for as many topics as you want.
Use study mode non-stop, no limits.
No annoying ads and popups. Study without distractions.
Track your scores over time in study mode and report cards.
See how you improve over time, and where you need to focus.
Access our store with even more discounts than before.
Unlimited access to all PBQs and be prepared for the real thing.
Create an account or sign in to access our study materials.