Which of the following is a type of vulnerability that involves inserting scripts into web-based applications in order to take control of the client's web browser?
Choose an answer
Tap an option to check your answer.
Correct answer: Cross-site scripting.
Why this is the answer
Cross-site scripting (XSS) is a vulnerability where attackers inject malicious scripts, typically JavaScript, into legitimate web pages. When a user visits the compromised page, their browser executes the script, allowing the attacker to steal cookies, session tokens, or deface the website. SQL injection targets databases by inserting malicious SQL queries into input fields, not client browsers. A zero-day exploit is a vulnerability unknown to the vendor, not a specific attack type. An on-path attack (formerly man-in-the-middle) intercepts communication between two parties, which is different from injecting scripts into a web application.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed