
EC-CouncilCertified Penetration Testing Professional
Domain 3Objective 1
Web Application Penetration Testing CPENT Practice Questions (Page 7)
Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.
63questions here
13free pages
16concepts
Questions 31–35
- 31
During a TLS assessment, you find that the server supports TLS 1.0 and uses RC4 cipher suites. The application also has a certificate that is not trusted by major browsers. Which issue is the most critical and should be prioritized in the report?
Select an answer first - 32
What is the purpose of including a risk rating in a penetration testing report?
Select an answer first - 33
You are testing a web application protected by a WAF. Your SQL injection payload 'UNION SELECT username, password FROM users' is blocked. You try URL encoding, but it is still blocked. Which technique is most likely to bypass the WAF while still executing the SQL injection?
Select an answer first - 34
A WAF blocks requests containing the string 'union select' in the query string. You need to test for SQL injection in a parameter that is reflected in a JSON response. Which technique is most likely to bypass the WAF while still being interpreted as a UNION-based SQL injection by the database?
Select an answer first - 35
Which of the following is a primary impact of a successful cross-site scripting (XSS) attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.