
EC-CouncilCertified Penetration Testing Professional
Domain 3Objective 2
API and Java Web Token Penetration Testing CPENT Practice Questions (Page 4)
Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.
68questions here
14free pages
17concepts
Questions 16–20
- 16
You are using Burp Suite to fuzz an API endpoint. You want to automate the discovery of SQL injection vulnerabilities in multiple parameters. Which approach is most effective?
Select an answer first - 17
You are testing an API login endpoint. The API uses JWTs for session management. You notice that the login endpoint does not have rate limiting, and the JWT secret is a common word. Which combination of attacks is most likely to succeed?
Select an answer first - 18
You need to automate fuzzing of an API's parameters to test for injection and unexpected behavior. Which tool is best suited for this task?
Select an answer first - 19
You are reviewing an API that uses API keys for authentication. You notice that the API key is sent as a query parameter in the URL. What is the primary security concern with this practice?
Select an answer first - 20
You are testing a REST API that accepts a 'userId' parameter. You want to identify injection points and unexpected behavior. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.