Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 3Objective 1

Web Application Penetration Testing CPENT Practice Questions (Page 6)

Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.

63questions here
13free pages
16concepts

Questions 26–30

  1. 26foundation · easy

    What is the primary difference between Server-Side Request Forgery (SSRF) and Cross-Site Request Forgery (CSRF)?

    Select an answer first
  2. 27foundation · easy

    A penetration tester discovers that a normal user can access another user's profile by changing the 'user_id' parameter in the URL. Which type of access control vulnerability is this?

    Select an answer first
  3. 28foundation · easy

    Which of the following is a recommended practice to prevent session fixation attacks?

    Select an answer first
  4. 29foundation · easy

    Which of the following is a gap in logging and monitoring that can allow an attacker to evade detection?

    Select an answer first
  5. 30foundation · easy

    Which threat modeling framework uses a structured approach to categorize threats into Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.