
EC-CouncilCertified Ethical Hacker
Domain 5Objective 2
Web Application Attacks and OWASP Top 10 CEH Practice Questions (Page 8)
Part of the Web Application Hacking domain, which makes up ~8% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~8–13 in this domain), expect 2–3 from this objective — we provide 61 practice questions to prepare you well beyond it. (estimate)
61questions here
13free pages
14concepts
Questions 36–40
- 36
A web application has a comment section where users can post messages. A security tester posts a comment containing the following script: <script>alert(document.cookie)</script>. When other users view the comment, the script executes in their browsers. Which type of XSS is this?
Select an answer first - 37
What is a potential consequence of insecure deserialization?
Select an answer first - 38
A penetration tester is assessing a web application that uses an LDAP directory for authentication. The tester submits the following input in the username field: *)(uid=*))(|(uid=* and successfully authenticates as the first user in the directory. The application uses a filter like (&(uid=USERNAME)(password=PASSWORD)). Which of the following is the most likely reason the attack succeeded?
Select an answer first - 39
A company's web application uses an open-source JavaScript library that is several versions behind. A security scan identifies that the library has a known critical vulnerability that allows remote code execution. Which of the following is the most appropriate immediate action?
Select an answer first - 40
A company's web application stores customer payment card data. A recent audit found that the data is stored in plaintext in the database and transmitted over HTTP on internal network segments. Which of the following is the most immediate risk to the company?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.