QUESTION IMAGE
Question
a web application with an sql server database is found to be compromised by an attacker. on examination, the email ids of the database have been found modified. this was due to improper validation in the input fields exploited by the attacker. what is the probable attack in the above scenario? xml injection sql injection xss ssrf question 10 2 pts jin is a project manager with an it firm, and his current project of developing an erp application is in the development stage. currently, the application is not yet mature or stable enough to be placed in a test environment. which of the following secure coding review techniques is applicable for his project? perform static code analysis perform dynamic code analysis perform a structured manual analysis of code perform a static binary code analysis
For the first question, since it's a web - application with an SQL server database and the attack exploited improper input - field validation to modify database content, SQL injection is the most likely attack as it targets SQL databases by injecting malicious SQL statements through input fields. For the second question, when the application is in the development stage and not stable enough for testing, static code analysis can be done without running the code to find security vulnerabilities.
Snap & solve any problem in the app
Get step-by-step solutions on Sovi AI
Photo-based solutions with guided steps
Explore more problems and detailed explanations
Question 9: B. SQL Injection
Question 10: A. Perform static code analysis