Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 5Objective 2

Web Application Attacks and OWASP Top 10 CEH Practice Questions (Page 11)

Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 61 practice questions to prepare you well beyond it. (estimate)

61questions here
13free pages
14concepts

Questions 51–55

  1. 51foundation · easy

    What is the most effective way to protect sensitive data at rest?

    Select an answer first
  2. 52expert · hard

    A security audit of a web application reveals that the server is running an outdated version of the web server software with known vulnerabilities. The application also has directory listing enabled, exposing sensitive files. Which of the following is the most comprehensive remediation?

    Select an answer first
  3. 53foundation · easy

    What is the primary goal of an LDAP injection attack?

    Select an answer first
  4. 54foundation · easy

    Which of the following is an example of privilege escalation?

    Select an answer first
  5. 55application · medium

    A security analyst is reviewing the OWASP Top 10 to prioritize remediation efforts for a web application. The application stores user session tokens in cookies without the Secure or HttpOnly flags, and it does not log failed login attempts. Which two OWASP Top 10 risk categories are most directly represented by these findings?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.