
EC-CouncilCertified Ethical Hacker
Domain 5Objective 2
Web Application Attacks and OWASP Top 10 CEH Practice Questions (Page 12)
Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 61 practice questions to prepare you well beyond it. (estimate)
61questions here
13free pages
14concepts
Questions 56–60
- 56
A security analyst is investigating a potential data breach. The web application logs authentication failures, but does not log successful logins or access to sensitive data. Which of the following is the most likely consequence of this logging gap?
Select an answer first - 57
A development team is fixing a stored XSS vulnerability in a web application. User-supplied comments are stored in a database and later displayed to other users. Which combination of defenses is most effective?
Select an answer first - 58
What is the first phase in a systematic web application testing methodology?
Select an answer first - 59
In a typical three-tier web application, which component is most directly responsible for processing business logic and interacting with the database?
Select an answer first - 60
Why is insufficient logging and monitoring a security risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.