
EC-CouncilCertified Ethical Hacker
Domain 5Objective 2
Web Application Attacks and OWASP Top 10 CEH Practice Questions (Page 10)
Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 61 practice questions to prepare you well beyond it. (estimate)
61questions here
13free pages
14concepts
Questions 46–50
- 46
What is the best practice to manage risks from outdated components?
Select an answer first - 47
What is a characteristic of a session fixation attack?
Select an answer first - 48
A security assessment of a web application reveals that the server returns detailed stack traces to users when an error occurs, and the default administrator account has not been disabled. Which of the following OWASP Top 10 categories best describes these findings?
Select an answer first - 49
Which scenario is an example of sensitive data exposure?
Select an answer first - 50
A web application allows users to view their own invoices by navigating to a URL like /invoice?id=12345. A tester changes the id parameter to 12346 and successfully views another user's invoice. Which of the following vulnerabilities is being exploited?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.