
EC-CouncilCertified Ethical Hacker
Domain 5Objective 2
Web Application Attacks and OWASP Top 10 CEH Practice Questions (Page 5)
Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 61 practice questions to prepare you well beyond it. (estimate)
61questions here
13free pages
14concepts
Questions 21–25
- 21
Which of the following is a common security misconfiguration?
Select an answer first - 22
A company's web application allows users to log in and then issues a session ID that remains valid for 30 days. The application does not rotate the session ID after login and does not invalidate sessions on the server when a user logs out. Which attack is most directly enabled by these weaknesses?
Select an answer first - 23
A web application has a search feature that reflects the user's query in the response without proper encoding. A penetration tester submits the following URL: /search?q=<script>alert(1)</script> and the script executes in the browser. Which type of XSS is this, and what is the most effective mitigation?
Select an answer first - 24
A penetration tester is assessing a web application. During the mapping phase, the tester identifies that the application uses predictable session IDs and that the /admin directory is accessible without authentication. The tester wants to prioritize testing based on the OWASP Top 10. Which two categories should the tester focus on first?
Select an answer first - 25
Which of the following is a common mitigation against XXE attacks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.