
EC-CouncilCertified Penetration Testing Professional
Domain 3Objective 2
API and Java Web Token Penetration Testing CPENT Practice Questions (Page 5)
Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.
68questions here
14free pages
17concepts
Questions 21–25
- 21
What is the primary defense against the JWT none algorithm attack?
Select an answer first - 22
Which type of input is commonly used in API parameter fuzzing to test for SQL injection?
Select an answer first - 23
Which of the following is a sign of weak API authentication that a tester should look for?
Select an answer first - 24
An API uses OAuth 2.0 with the authorization code grant. You intercept an authorization code and notice that it can be used multiple times. Which flaw is this?
Select an answer first - 25
Which JWT attack is possible when a server uses HS256 and the HMAC secret is a short, easily guessable value?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.