
EC-CouncilCertified Ethical Hacker
Domain 5Objective 2
Web Application Attacks and OWASP Top 10 CEH Practice Questions (Page 3)
Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 61 practice questions to prepare you well beyond it. (estimate)
61questions here
13free pages
14concepts
Questions 11–15
- 11
What is the primary purpose of the OWASP Top 10 publication?
Select an answer first - 12
A web application stores user passwords using the MD5 hash algorithm without a salt. A penetration tester obtains the password hash database and is able to quickly recover many plaintext passwords using a rainbow table. Which of the following is the most effective remediation to prevent this from happening in the future?
Select an answer first - 13
Which of the following is an example of an attack surface introduced by the client-side component of a web application?
Select an answer first - 14
Which of the following is a recommended defense against insecure deserialization?
Select an answer first - 15
A security analyst is reviewing the logging configuration of a web application. The application logs all successful logins and all errors, but it does not log failed login attempts or access to administrative functions. Which improvement is most important for detecting a brute-force attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.