
EC-CouncilCertified Ethical Hacker
Domain 5Objective 2
Web Application Attacks and OWASP Top 10 CEH Practice Questions (Page 11)
Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 61 practice questions to prepare you well beyond it. (estimate)
61questions here
13free pages
14concepts
Questions 51–55
- 51
What is the most effective way to protect sensitive data at rest?
Select an answer first - 52
A security audit of a web application reveals that the server is running an outdated version of the web server software with known vulnerabilities. The application also has directory listing enabled, exposing sensitive files. Which of the following is the most comprehensive remediation?
Select an answer first - 53
What is the primary goal of an LDAP injection attack?
Select an answer first - 54
Which of the following is an example of privilege escalation?
Select an answer first - 55
A security analyst is reviewing the OWASP Top 10 to prioritize remediation efforts for a web application. The application stores user session tokens in cookies without the Secure or HttpOnly flags, and it does not log failed login attempts. Which two OWASP Top 10 risk categories are most directly represented by these findings?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.