
EC-CouncilCertified Cybersecurity Technician
Domain 3Objective 2
Application Security CCT Practice Questions (Page 1)
Part of the Security Assessment and Application Security domain, which makes up ~9% of our current practice bank.
51questions here
11free pages
10concepts
Questions 1–5
- 1
A development team is about to release a web application. They want to identify vulnerabilities in the source code before deployment, focusing on issues like SQL injection and insecure deserialization. Which testing method should they use?
Select an answer first - 2
A retail company's web application allows customers to search products by entering a keyword in a URL parameter. A penetration test reveals that an attacker can modify the parameter to `' OR '1'='1` and retrieve all customer records from the database. The development team is asked to remediate this immediately. Which combination of controls should be prioritized?
Select an answer first - 3
Which application security threat is characterized by an attacker guessing or obtaining valid credentials to impersonate a legitimate user?
Select an answer first - 4
A company is designing a public API that will be used by mobile clients. The API handles sensitive user data. The security team wants to ensure that each request is authenticated and that users can only access their own data. They also want to avoid storing long-lived secrets on the mobile device. Which authentication approach is BEST?
Select an answer first - 5
Which secure coding practice is most effective in preventing SQL injection vulnerabilities?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.