Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Cybersecurity Technician

Domain 3Objective 2

Application Security CCT Practice Questions (Page 7)

Part of the Security Assessment and Application Security domain, which makes up ~9% of our current practice bank.

51questions here
11free pages
10concepts

Questions 31–35

  1. 31expert · hard

    A company has a public-facing web application protected by a WAF. The WAF is blocking legitimate users because of false positives. The security team needs to reduce false positives without weakening security. Which action is most effective?

    Select an answer first
  2. 32foundation · easy

    Which of the following best describes an SQL injection attack?

    Select an answer first
  3. 33foundation · easy

    After an application security incident has been contained and eradicated, what is the next step in the incident response process?

    Select an answer first
  4. 34application · medium

    A company deploys a Web Application Firewall (WAF) in front of its public-facing web application. The security team wants to reduce false positives while still blocking common attacks. Which WAF configuration approach is most effective?

    Select an answer first
  5. 35application · medium

    A company exposes a REST API for partners to retrieve order status. The API uses API keys passed in the URL query string. A security review finds that the keys are logged by the web server and can be leaked via browser history and referrer headers. Which change should be made to improve API security?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.