
EC-CouncilCertified Ethical Hacker
Domain 5Objective 2
Web Application Attacks and OWASP Top 10 CEH Practice Questions (Page 6)
Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 61 practice questions to prepare you well beyond it. (estimate)
61questions here
13free pages
14concepts
Questions 26–30
- 26
A web application is vulnerable to reflected XSS. The development team wants to implement a defense that prevents the browser from executing inline scripts. Which security header is most effective for this purpose?
Select an answer first - 27
A web application has an administrative interface that is accessible at /admin. The application checks for an 'isAdmin' flag in the user's session. A penetration tester changes the 'isAdmin' flag from false to true in the session cookie and gains administrative access. Which of the following is the most likely vulnerability?
Select an answer first - 28
A penetration tester is performing a web application assessment. The tester has completed reconnaissance and identified a login form that appears to be vulnerable to SQL injection. The tester wants to confirm the vulnerability with minimal risk of causing data loss. Which technique is most appropriate?
Select an answer first - 29
A penetration tester is testing a web application that parses XML documents. The tester uploads an XML file that includes an external entity pointing to an internal server URL. The application responds with the internal server's response. Which of the following is the most likely impact of this vulnerability?
Select an answer first - 30
What is a key element of effective logging and monitoring?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.