
EC-CouncilCertified Penetration Testing Professional
Domain 3Objective 1
Web Application Penetration Testing CPENT Practice Questions (Page 4)
Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.
63questions here
13free pages
16concepts
Questions 16–20
- 16
A penetration tester wants to identify the web server software, version, and operating system of a target web application without sending any packets directly to the target. Which technique would be most appropriate?
Select an answer first - 17
Which type of injection attack targets a database that stores data in JSON-like documents and uses queries that resemble JavaScript syntax?
Select an answer first - 18
You are threat modeling a web application that handles financial transactions. The application has a user role and an admin role. You have identified that the 'transfer funds' function is available to both roles, but the admin role has additional features. You need to prioritize vulnerabilities based on business logic and technical exposure. Which vulnerability should be prioritized as the highest risk?
Select an answer first - 19
A REST API uses OAuth 2.0 with the implicit grant flow for a single-page application. The API returns sensitive user data and uses CORS with a wildcard origin. You discover that the API does not validate the 'state' parameter. Which combination of vulnerabilities is most critical?
Select an answer first - 20
During the reconnaissance phase of a web application penetration test, a tester uses the website's robots.txt file and sitemap.xml to discover hidden directories and endpoints. Which type of information gathering technique is being employed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.