312-50v13 Exam Question 251
You are investigating unauthorized access to a web application using token-based authentication. Tokens expire after 30 minutes. Server logs show multiple failed login attempts using expired tokens within a short window, followed by successful access with a valid token. What is the most likely attack scenario?
312-50v13 Exam Question 252
A sophisticated injection attack bypassed validation using obfuscation. What is the best future defense?
312-50v13 Exam Question 253
A Linux system allows passwordless sudo for multiple commands. What security principle is violated?
312-50v13 Exam Question 254
A penetration tester is assessing a web application that does not properly sanitize user input in the search field. The tester suspects the application is vulnerable to a SQL injection attack. Which approach should the tester take to confirm the vulnerability?
312-50v13 Exam Question 255
A payload causes a significant delay in response without visible output when testing an Oracle-backed application. What SQL injection technique is being used?
