Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 3Objective 2

API and Java Web Token Penetration Testing CPENT Practice Questions (Page 14)

Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.

68questions here
14free pages
17concepts

Questions 66–68

  1. 66expert · hard

    During an API assessment, you find that the API returns verbose error messages that include SQL queries. You also notice that the API exposes an undocumented endpoint that allows user enumeration. Which misconfiguration is the most critical to report?

    Select an answer first
  2. 67foundation · easy

    What is the first phase in a structured API penetration testing methodology?

    Select an answer first
  3. 68application · medium

    You are starting an API penetration test. You have a valid API key and the base URL. Which sequence of steps best follows a structured methodology?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CPENT

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.