Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 3Objective 2

API and Java Web Token Penetration Testing CPENT Practice Questions (Page 6)

Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.

68questions here
14free pages
17concepts

Questions 26–30

  1. 26application · medium

    While testing an API, you find that the server accepts JWTs with the algorithm 'none'. You want to exploit this to access another user's account. What is the most direct way to do this?

    Select an answer first
  2. 27foundation · easy

    Why is it important to analyze the API's functionality before attempting exploitation?

    Select an answer first
  3. 28application · medium

    You are testing an API login endpoint that uses OAuth2 and JWT. You want to assess whether the endpoint is vulnerable to brute-force attacks. Which action is most appropriate?

    Select an answer first
  4. 29application · medium

    An API uses API keys for authentication. You notice that the API key is a sequential number and that the server does not check if the key is active. Which vulnerability is most directly indicated?

    Select an answer first
  5. 30expert · hard

    You are testing an API login endpoint. The API uses OAuth2 and JWT. You have a list of valid usernames and want to test for credential stuffing. The API has rate limiting that blocks after 5 failed attempts per IP. Which approach is most likely to bypass the rate limit while still testing the vulnerability?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.