Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 3Objective 2

API and Java Web Token Penetration Testing CPENT Practice Questions (Page 2)

Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.

68questions here
14free pages
17concepts

Questions 6–10

  1. 6foundation · easy

    What is the primary difference between HS256 and RS256 JWT signing algorithms?

    Select an answer first
  2. 7application · medium

    During an API test, you find that the API returns full stack traces and internal IP addresses in error messages. Which security misconfiguration is this?

    Select an answer first
  3. 8foundation · easy

    Which tool is commonly used to intercept, modify, and replay API requests for fuzzing?

    Select an answer first
  4. 9application · medium

    You are testing an API endpoint that accepts a 'search' parameter. You send the value "' OR '1'='1" and the API returns all records. Which vulnerability is present?

    Select an answer first
  5. 10foundation · easy

    Why is RS256 generally considered more secure than HS256 for JWT signing in a distributed system?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.