Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 5Objective 2

Web Application Attacks and OWASP Top 10 CEH Practice Questions (Page 2)

Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 61 practice questions to prepare you well beyond it. (estimate)

61questions here
13free pages
14concepts

Questions 6–10

  1. 6expert · hard

    A web application has a search feature that is vulnerable to SQL injection. The application uses a WAF that blocks common SQL keywords like UNION and SELECT. The tester wants to extract data from the database. Which technique is most likely to bypass the WAF?

    Select an answer first
  2. 7application · medium

    A web application allows users to enter their name, which is displayed on their profile page. To prevent stored XSS attacks, which of the following is the most effective defense?

    Select an answer first
  3. 8foundation · easy

    Why is using a library with a known critical vulnerability a security risk?

    Select an answer first
  4. 9application · medium

    A security analyst is investigating a suspected data breach. The application logs successful logins but does not log failed login attempts or access to sensitive data. Which OWASP Top 10 category is most directly related to this gap?

    Select an answer first
  5. 10foundation · easy

    Which security header helps prevent MIME type sniffing attacks?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.