Community QuestionSeen on 4 CBTsRe-created in 9 study sets this year

Cross-site scripting (XSS)

Community-sourced. Answers may be wrong or out of date. Always verify with your official training portal before submitting. Not affiliated with any branch, agency, or vendor. Details.
Answer

An attacker discovered an input validation vulnerability on a website, crafted a URL with additional HTML code, and emailed the link to a victim. The victim unknowingly defaced (vandalized) the web site after clicking on the malicious URL. No other malicious operations occurred outside of the web application's root directory. This scenario is describing which type of attack?

2 of 4 indexed CBT versions give this answer·Answer index rebuilt Aug 10, 2026

The indexed versions don't agree on this one

This question appears on 4 CBT versions we've indexed, and they don't all give the same answer. Exam editions change and answer keys get re-cut, so more than one of these was correct on the test it came from. Here is each of them, and how many versions give it.

2 of 4 versionsmost versions

An attacker discovered an input validation vulnerability on a website, crafted a URL with additional HTML code, and emailed the link to a victim. The victim unknowingly defaced (vandalized) the web site after clicking on the malicious URL. No other malicious operations occurred outside of the web application's root directory. This scenario is describing which type of attack?

Comptia Certmaster Practice For Security+ Sy0 601 · Comptia Security+ Practice Exam Sy0 601

1 of 4 version

is a malicious script hosted on the attacker's site or coded in a link injected onto a trusted site designed to compromise clients browsing the trusted site.

Comptia Certmaster Practice For Security+

1 of 4 version

A web security vulnerability that allows an attacker to compromise the interactions that users have with a vulnerable application. It allows an attacker to circumvent the same origin policy, which is designed to segregate different websites from each other.

Comptia Exam Objectives Security+

Know which one your test keyed? One click. No account needed.