Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 3Objective 1

Web Application Penetration Testing CPENT Practice Questions (Page 10)

Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.

63questions here
13free pages
16concepts

Questions 46–50

  1. 46application · medium

    You are testing a REST API that uses API keys in the Authorization header. The API returns full user objects, including password hashes, when a client requests /users/{id}. You also notice that the API does not enforce rate limiting on the login endpoint. Which two findings should you report?

    Select an answer first
  2. 47foundation · easy

    In API security testing, what does 'mass assignment' refer to?

    Select an answer first
  3. 48application · medium

    You are testing a REST API that uses JWT for authentication. The API has an endpoint '/api/users/{id}' that returns user details. You discover that by changing the 'id' parameter, you can access other users' data without authorization. The API also accepts a 'role' field in the POST request to '/api/users' and sets the user's role to whatever is provided. Which two vulnerabilities are present?

    Select an answer first
  4. 49expert · hard

    A web application has a search feature that is vulnerable to SQL injection, but a WAF blocks common payloads. You have confirmed the injection exists by using a boolean-based blind technique. You now need to extract data, but the WAF also blocks the keywords 'union', 'select', and 'from'. Which approach is most likely to succeed?

    Select an answer first
  5. 50foundation · easy

    In threat modeling for a web application, which activity is primarily used to identify and prioritize potential attack vectors based on the application's architecture and data flow?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.