
EC-CouncilCertified Cybersecurity Technician
Domain 3Objective 2
Application Security CCT Practice Questions (Page 4)
Part of the Security Assessment and Application Security domain, which makes up ~9% of our current practice bank.
51questions here
11free pages
10concepts
Questions 16–20
- 16
An organization's web application uses session cookies for authentication. A security audit reveals that the session ID is predictable and that the cookie is not marked with the `Secure` or `HttpOnly` attributes. Which combination of changes should be made to harden the session management?
Select an answer first - 17
A developer is writing a web form that accepts user comments and displays them on a public page. The application currently inserts the raw user input directly into the HTML. A security tester finds that a user can submit `<script>alert(document.cookie)</script>` and it executes in other users' browsers. Which secure coding practice should the developer apply?
Select an answer first - 18
What is the purpose of output encoding in secure coding?
Select an answer first - 19
A system administrator is deploying a web application to a production server. The application stores sensitive user data. Which configuration practice is most important to reduce the risk of data exposure?
Select an answer first - 20
A development team is fixing a stored XSS vulnerability in a web application. The application allows users to submit rich text (including HTML) that is rendered to other users. The team must preserve the rich text functionality while preventing script execution. Which approach is most secure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.