Continue your lesson
Connect each term to the asset, threat, control, and evidence it affects.
Block 1 of 1Compare SQL injection · Cross-site scripting · Buffer overflow · Virtual machine escape
Current · 15 min
Compare SQL injection · Cross-site scripting · Buffer overflow · Virtual machine escape
Optional concept notes
SQL injection
Manipulates database queries through untrusted application input.
Cross-site scripting
Runs attacker-controlled browser script through unsafely rendered content.
Buffer overflow
Writes beyond allocated memory and can alter program execution.
Virtual machine escape
Crosses guest isolation to affect a hypervisor or host.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Practice the reasoning here
Use a fictional organization. Name the risk, choose the narrowest useful control, and state what evidence would prove the control worked.
- State the expected result before changing or testing anything.
- Name the observation, command, log, or report that would confirm it.
- Explain why the closest alternative does not fit the same requirement.
Check the whole objective
This unlocks objective 2.3 for recall. The latest checkpoint needs 70% or higher; a lower result puts the lesson back near the front of your timeline.