
EC-CouncilCertified Penetration Testing Professional
Domain 3Objective 2
API and Java Web Token Penetration Testing CPENT Practice Questions (Page 2)
Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.
68questions here
14free pages
17concepts
Questions 6–10
- 6
What is the primary difference between HS256 and RS256 JWT signing algorithms?
Select an answer first - 7
During an API test, you find that the API returns full stack traces and internal IP addresses in error messages. Which security misconfiguration is this?
Select an answer first - 8
Which tool is commonly used to intercept, modify, and replay API requests for fuzzing?
Select an answer first - 9
You are testing an API endpoint that accepts a 'search' parameter. You send the value "' OR '1'='1" and the API returns all records. Which vulnerability is present?
Select an answer first - 10
Why is RS256 generally considered more secure than HS256 for JWT signing in a distributed system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.