Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil Exam 312-49 Topic 1 Question 59 Discussion

Actual exam question for Eccouncil's 312-49 exam
Question #: 59
Topic #: 1
[All 312-49 Questions]

You are the incident response manager at a regional bank. While performing routine auditing of web application logs, you find several attempted login submissions that contain the following strings:

What kind of attack has occurred?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

Franchesca
5 months ago
I think it's definitely SQL injection, the strings match the pattern.
upvoted 0 times
...
Naomi
5 months ago
I'm not sure, but it could also be a cross-site scripting attack.
upvoted 0 times
...
Freeman
5 months ago
Haha, I bet the bank's IT team is having a field day with this one. Probably SQL injection, though I can't rule out cross-site request forgery either.
upvoted 0 times
Amira
4 months ago
The IT team must be working hard to address this security issue.
upvoted 0 times
...
Lindsey
4 months ago
I agree, it could be SQL injection or cross-site request forgery.
upvoted 0 times
...
...
Leatha
5 months ago
I agree with Catalina, the strings look like SQL injection attempts.
upvoted 0 times
...
Laura
6 months ago
Hmm, I'm not sure. Could be a buffer overflow, but the login context makes me think it's more likely a SQL injection attack.
upvoted 0 times
...
Catalina
6 months ago
I think it's a SQL injection attack.
upvoted 0 times
...
Esteban
6 months ago
I'm leaning towards cross-site scripting (XSS) here. Those funny-looking strings could be part of an XSS payload.
upvoted 0 times
Cherilyn
5 months ago
We should investigate further to confirm if it's indeed a cross-site scripting attack.
upvoted 0 times
...
Cherilyn
5 months ago
I agree, those strings look suspicious. It could definitely be a cross-site scripting attack.
upvoted 0 times
...
...
Dwight
6 months ago
Definitely SQL injection, those strings look like an attempt to exploit the application's input validation.
upvoted 0 times
Dan
5 months ago
I think it's actually SQL injection. The attackers are trying to inject malicious SQL code into the login form.
upvoted 0 times
...
Charlette
5 months ago
C) Cross-site scripting
upvoted 0 times
...
Paola
5 months ago
Yes, I agree. The strings in the login submissions definitely look like they are trying to manipulate the SQL queries.
upvoted 0 times
...
Cecily
5 months ago
A) SQL injection
upvoted 0 times
...
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77