Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 3Objective 2

API and Java Web Token Penetration Testing CPENT Practice Questions (Page 5)

Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.

68questions here
14free pages
17concepts

Questions 21–25

  1. 21foundation · easy

    What is the primary defense against the JWT none algorithm attack?

    Select an answer first
  2. 22foundation · easy

    Which type of input is commonly used in API parameter fuzzing to test for SQL injection?

    Select an answer first
  3. 23foundation · easy

    Which of the following is a sign of weak API authentication that a tester should look for?

    Select an answer first
  4. 24application · medium

    An API uses OAuth 2.0 with the authorization code grant. You intercept an authorization code and notice that it can be used multiple times. Which flaw is this?

    Select an answer first
  5. 25foundation · easy

    Which JWT attack is possible when a server uses HS256 and the HMAC secret is a short, easily guessable value?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.