
EC-CouncilCertified Ethical Hacker
Domain 5Objective 4
API and Webhook Hacking CEH Practice Questions (Page 6)
Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 26–30
- 26
An attacker sends the following payload to an API endpoint: `username=admin' OR '1'='1`. Which type of attack is being attempted?
Select an answer first - 27
Which of the following is a common technique used to bypass API rate limiting?
Select an answer first - 28
A payment gateway sends webhook notifications to a merchant's endpoint to update order status. A security tester finds that the endpoint accepts any POST request and processes the payload without verifying a signature. Which of the following is the most effective control to prevent an attacker from sending fake 'payment_succeeded' events?
Select an answer first - 29
A SaaS company receives webhooks from multiple clients. Each webhook triggers a series of database updates and external API calls. An attacker floods the webhook endpoint with thousands of requests per second, causing the backend to become unresponsive. Which of the following is the most effective mitigation?
Select an answer first - 30
A company exposes an internal API for employee management. A security review reveals that the API responds to OPTIONS requests with a list of allowed methods including DELETE, and that error messages include full stack traces. Which of the following is the most appropriate action to harden the API?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.