
EC-CouncilCertified Ethical Hacker
Domain 5Objective 4
API and Webhook Hacking CEH Practice Questions (Page 10)
Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 46–46
- 46
An attacker sends a `PUT /api/users/123` request with the JSON body `{"username":"newuser","role":"admin"}`. The API updates the user's role to admin. Which vulnerability is being exploited?
Select an answer first
Finished these 1 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CEH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.