
EC-CouncilCertified Penetration Testing Professional
Domain 3Objective 2
API and Java Web Token Penetration Testing CPENT Practice Questions (Page 12)
Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.
68questions here
14free pages
17concepts
Questions 56–60
- 56
You are testing an API endpoint that accepts a 'user_id' parameter. You want to identify injection vulnerabilities. Which approach is most effective?
Select an answer first - 57
You are leading an API penetration test. The client has limited time and budget. You need to prioritize testing activities. Which sequence of activities is most effective for identifying high-impact vulnerabilities?
Select an answer first - 58
What is a common way attackers bypass API rate limiting?
Select an answer first - 59
After an attacker modifies the payload of a JWT, what must they also do for the token to be accepted by a properly configured server?
Select an answer first - 60
You are performing an API assessment and have discovered the base URL https://api.example.com/v1/. The API documentation is not public. Which method is most effective for discovering hidden endpoints?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.