Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 5Objective 2

Web Application Attacks and OWASP Top 10 CEH Practice Questions (Page 4)

Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 61 practice questions to prepare you well beyond it. (estimate)

61questions here
13free pages
14concepts

Questions 16–20

  1. 16application · medium

    A penetration tester is testing a web application that accepts XML uploads. The tester uploads an XML file containing an external entity that references a local file path. The application returns the contents of that file in the response. Which of the following is the most likely vulnerability?

    Select an answer first
  2. 17application · medium

    A web application deserializes Java objects from a cookie to maintain user session state. A penetration tester modifies the cookie to include a malicious serialized object that executes a command on the server. Which of the following vulnerabilities is being exploited?

    Select an answer first
  3. 18expert · hard

    A web application uses role-based access control (RBAC). A low-privileged user discovers that by changing a hidden form field from 'role=user' to 'role=admin', they gain administrative privileges. Which type of access control flaw is this?

    Select an answer first
  4. 19application · medium

    A security analyst notices that a web application's login page does not invalidate the session ID when a user logs out. An attacker who obtains a valid session ID can reuse it after the victim logs out. Which of the following attacks is the analyst most likely observing?

    Select an answer first
  5. 20application · medium

    A penetration tester is beginning an assessment of a web application. The tester uses a spider to crawl the application, identifies all input parameters, and maps the application's functionality. Which phase of the web application attack methodology is the tester performing?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.