a security consultant recently audited a company's cloud resources and web services. the consultant found ineffective secrets management and a lack of input validation mechanisms. what type of attack would the company's cloud resources be susceptible to at its current state? (select all that apply.)