
EC-CouncilCertified Ethical Hacker
Domain 5Objective 4
API and Webhook Hacking CEH Practice Questions (Page 8)
Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
8concepts
Questions 36–40
- 36
A company exposes a public API for checking order status. The API uses API keys for authentication and has a rate limit of 100 requests per minute per key. An attacker creates multiple free accounts to obtain multiple API keys and uses them to rotate through the keys, bypassing the per-key rate limit and overwhelming the backend. Which mitigation would be most effective?
Select an answer first - 37
A company exposes a public API endpoint that triggers a webhook to a third-party service. An attacker sends thousands of requests per second to the endpoint, causing the webhook to flood the third-party service and exhaust its resources. Which two controls should the company implement to mitigate this attack?
Select an answer first - 38
Which API injection attack involves inserting malicious code into a query that is executed by a non-relational database, such as MongoDB?
Select an answer first - 39
Which of the following is an example of an API security misconfiguration?
Select an answer first - 40
A company exposes a public API that triggers webhooks to a third-party service. The API has a rate limit of 10 requests per second per IP address. An attacker uses a botnet to send requests from thousands of different IP addresses, each staying below the rate limit, but collectively overwhelming the webhook receiver. Which mitigation would be most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.