nerdexam
CompTIACompTIA

CS0-003 · Question #384

CS0-003 Question #384: Real Exam Question with Answer & Explanation

Sign in or unlock CS0-003 to reveal the answer and full explanation for question #384. The question stem and answer options stay visible for context.

Submitted by yasin.bd· Mar 6, 2026Vulnerability Management

Question

A security analyst recently used Arachni to perform a vulnerability assessment of a newly developed web application. The analyst is concerned about the following output: [+] XSS: In form input 'txtSearch' with action https://localhost/search.aspx [-] XSS: Analyzing response #1... [-] XSS: Analyzing response #2... [-] XSS: Analyzing response #3... [+] XSS: Response is tainted. Looking for proof of the vulnerability. Which of the following is the most likely reason for this vulnerability?

Options

  • AThe developer set input validation protection on the specific field of search.aspx.
  • BThe developer did not set proper cross-site scripting protections in the header.
  • CThe developer did not implement default protections in the web application build.
  • DThe developer did not set proper cross-site request forgery protections.

Unlock CS0-003 to see the answer

You've previewed enough free CS0-003 questions. Unlock CS0-003 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Vulnerability Assessment#Web Application Security#Cross-Site Scripting (XSS)#Security Headers
Full CS0-003 PracticeBrowse All CS0-003 Questions