
EC-CouncilCertified Ethical Hacker
Domain 5Objective 2
Web Application Attacks and OWASP Top 10 CEH Practice Questions (Page 7)
Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 61 practice questions to prepare you well beyond it. (estimate)
61questions here
13free pages
14concepts
Questions 31–35
- 31
A healthcare web application transmits patient records over HTTPS but stores them in a database without encryption. An attacker who gains access to the database can read all patient data in plaintext. Which OWASP Top 10 category best describes this vulnerability?
Select an answer first - 32
A web application has a page that reads a URL parameter and uses it to update the DOM via JavaScript. The server does not reflect the parameter in the HTML response. A tester discovers that the parameter is inserted into the DOM without sanitization. Which type of XSS is this?
Select an answer first - 33
A web application uses Java serialization to store user session data in a cookie. A penetration tester crafts a malicious serialized object and sends it in the cookie. The application deserializes the object, leading to arbitrary command execution on the server. Which of the following is the most effective mitigation?
Select an answer first - 34
Which attack involves using previously breached username and password pairs to gain unauthorized access to a different application?
Select an answer first - 35
Which of the following is listed in the OWASP Top 10 as a distinct security risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.