Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 3Objective 2

API and Java Web Token Penetration Testing CPENT Practice Questions (Page 9)

Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.

68questions here
14free pages
17concepts

Questions 41–45

  1. 41application · medium

    You are testing an API that allows users to view their own orders. When you change the 'orderId' in the request to another user's order, the API returns that order's details. Which vulnerability is this?

    Select an answer first
  2. 42foundation · easy

    Which of the following is a feature of Postman that is useful for API fuzzing?

    Select an answer first
  3. 43expert · hard

    You are testing an API that uses JWTs. The server supports both HS256 and RS256. You have obtained the server's public key. Which attack is most likely to succeed if the server does not validate the algorithm?

    Select an answer first
  4. 44application · medium

    You are testing an API endpoint that accepts a 'search' parameter. You want to test for command injection. Which payload is most appropriate to send?

    Select an answer first
  5. 45foundation · easy

    What is the purpose of rate limiting in an API?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.