
EC-CouncilCertified Penetration Testing Professional
Domain 3Objective 2
API and Java Web Token Penetration Testing CPENT Practice Questions (Page 13)
Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.
68questions here
14free pages
17concepts
Questions 61–65
- 61
You are testing a web API that issues JWTs signed with HS256. You have captured a token and suspect the secret is weak. Which approach is most efficient to verify this and forge a valid token?
Select an answer first - 62
Which type of injection attack involves sending malicious input that is executed as operating system commands by the API server?
Select an answer first - 63
Which of the following is a common source for discovering API endpoints during enumeration?
Select an answer first - 64
You are testing an API login endpoint. You notice that the API does not limit the number of login attempts. Which attack is most directly enabled?
Select an answer first - 65
You have captured a JWT from an API. The token uses HS256 and you have successfully cracked the secret. Which action allows you to escalate privileges?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.