
EC-CouncilCertified Penetration Testing Professional
Domain 3Objective 1
Web Application Penetration Testing CPENT Practice Questions (Page 11)
Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.
63questions here
13free pages
16concepts
Questions 51–55
- 51
You are testing a search feature that reflects user input in an error message. The application is behind a WAF that blocks common SQL injection patterns like ' OR 1=1--. Which technique is most likely to bypass the WAF and still confirm a SQL injection vulnerability?
Select an answer first - 52
Which of the following is a common security issue in REST APIs?
Select an answer first - 53
While testing a blog application, you find that the 'author' parameter in the URL is reflected in the page without sanitization. You craft a payload that steals the session cookie and sends it to your server. The payload executes in the browser of any user who clicks your crafted link. Which type of XSS is this, and what is the most direct impact you can demonstrate?
Select an answer first - 54
During a penetration test of a corporate web application, you notice that the server responds with detailed stack traces and the HTTP headers reveal the exact web server version and framework. The application also allows weak TLS ciphers. Which finding should be prioritized in your report as the most critical security misconfiguration?
Select an answer first - 55
Which of the following is an example of a security misconfiguration in a web application?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.