Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Cybersecurity Technician

Domain 3Objective 2

Application Security CCT Practice Questions (Page 3)

Part of the Security Assessment and Application Security domain, which makes up ~9% of our current practice bank.

51questions here
11free pages
10concepts

Questions 11–15

  1. 11foundation · easy

    What is the primary role of a Web Application Firewall (WAF)?

    Select an answer first
  2. 12foundation · easy

    Which type of attack is a Web Application Firewall (WAF) specifically designed to mitigate?

    Select an answer first
  3. 13application · medium

    An e-commerce site is experiencing a spike in automated attacks that exploit a known SQL injection flaw in a legacy module. The module cannot be patched immediately. The security team wants to reduce risk while the patch is developed. What is the most effective immediate control?

    Select an answer first
  4. 14expert · hard

    A web application uses session cookies for authentication. The security team discovers that an attacker can hijack a user's session by intercepting the cookie. The application is accessed over HTTPS. Which additional control is most effective to prevent session hijacking?

    Select an answer first
  5. 15foundation · easy

    Which security testing method simulates real-world attacks to identify exploitable vulnerabilities in a running application?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.