Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 3Objective 1

Web Application Penetration Testing CPENT Practice Questions (Page 5)

Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.

63questions here
13free pages
16concepts

Questions 21–25

  1. 21application · medium

    You have completed a penetration test and found a critical SQL injection in a login form, a medium-severity missing HSTS header, and a low-severity verbose error message. Which reporting approach best communicates the findings to both developers and management?

    Select an answer first
  2. 22foundation · easy

    Which HTTP method is most commonly targeted in CSRF attacks because it changes server state?

    Select an answer first
  3. 23application · medium

    During a web application penetration test, you notice that after a user logs out, the session ID remains valid and can be replayed to access the account. The application also allows a logged-in user to change their own role by sending a modified POST request. Which two weaknesses are most directly demonstrated by these observations?

    Select an answer first
  4. 24foundation · easy

    Which technique is commonly used to bypass a Web Application Firewall (WAF) when injecting SQL payloads?

    Select an answer first
  5. 25application · medium

    You are starting a web application penetration test. The client has provided only the domain name. Which combination of passive and active reconnaissance techniques would give you the most comprehensive understanding of the attack surface before you begin testing?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.