
EC-CouncilCertified Penetration Testing Professional
Domain 3Objective 1
Web Application Penetration Testing CPENT Practice Questions (Page 6)
Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.
63questions here
13free pages
16concepts
Questions 26–30
- 26
What is the primary difference between Server-Side Request Forgery (SSRF) and Cross-Site Request Forgery (CSRF)?
Select an answer first - 27
A penetration tester discovers that a normal user can access another user's profile by changing the 'user_id' parameter in the URL. Which type of access control vulnerability is this?
Select an answer first - 28
Which of the following is a recommended practice to prevent session fixation attacks?
Select an answer first - 29
Which of the following is a gap in logging and monitoring that can allow an attacker to evade detection?
Select an answer first - 30
Which threat modeling framework uses a structured approach to categorize threats into Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.