Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 3Objective 2

API and Java Web Token Penetration Testing CPENT Practice Questions (Page 12)

Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.

68questions here
14free pages
17concepts

Questions 56–60

  1. 56application · medium

    You are testing an API endpoint that accepts a 'user_id' parameter. You want to identify injection vulnerabilities. Which approach is most effective?

    Select an answer first
  2. 57expert · hard

    You are leading an API penetration test. The client has limited time and budget. You need to prioritize testing activities. Which sequence of activities is most effective for identifying high-impact vulnerabilities?

    Select an answer first
  3. 58foundation · easy

    What is a common way attackers bypass API rate limiting?

    Select an answer first
  4. 59foundation · easy

    After an attacker modifies the payload of a JWT, what must they also do for the token to be accepted by a properly configured server?

    Select an answer first
  5. 60application · medium

    You are performing an API assessment and have discovered the base URL https://api.example.com/v1/. The API documentation is not public. Which method is most effective for discovering hidden endpoints?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.