
EC-CouncilCertified Penetration Testing Professional
Domain 3Objective 2
API and Java Web Token Penetration Testing CPENT Practice Questions (Page 6)
Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.
68questions here
14free pages
17concepts
Questions 26–30
- 26
While testing an API, you find that the server accepts JWTs with the algorithm 'none'. You want to exploit this to access another user's account. What is the most direct way to do this?
Select an answer first - 27
Why is it important to analyze the API's functionality before attempting exploitation?
Select an answer first - 28
You are testing an API login endpoint that uses OAuth2 and JWT. You want to assess whether the endpoint is vulnerable to brute-force attacks. Which action is most appropriate?
Select an answer first - 29
An API uses API keys for authentication. You notice that the API key is a sequential number and that the server does not check if the key is active. Which vulnerability is most directly indicated?
Select an answer first - 30
You are testing an API login endpoint. The API uses OAuth2 and JWT. You have a list of valid usernames and want to test for credential stuffing. The API has rate limiting that blocks after 5 failed attempts per IP. Which approach is most likely to bypass the rate limit while still testing the vulnerability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.