Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Cybersecurity Technician

Domain 3Objective 2

Application Security CCT Practice Questions (Page 2)

Part of the Security Assessment and Application Security domain, which makes up ~9% of our current practice bank.

51questions here
11free pages
10concepts

Questions 6–10

  1. 6application · medium

    An application uses role-based access control (RBAC). A user with the 'viewer' role is able to access an administrative endpoint by manually changing the URL. What is the most likely root cause and fix?

    Select an answer first
  2. 7expert · hard

    A company is implementing role-based access control (RBAC) for a new application. The application has three roles: User, Manager, and Admin. A Manager should be able to view and edit reports created by users in their department, but not delete them. Admins can do everything. The current implementation allows any authenticated user to edit any report. What is the most effective way to enforce the required access control?

    Select an answer first
  3. 8application · medium

    A company's web application is defaced and the homepage is replaced with a malicious message. The security team suspects an unpatched plugin was exploited. What is the FIRST step in the incident response process for this application?

    Select an answer first
  4. 9foundation · easy

    In the context of the software development lifecycle (SDLC), what is the primary purpose of application security?

    Select an answer first
  5. 10foundation · easy

    Which technique is used to protect sensitive data at rest in a database?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.