Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 3Objective 1

Web Application Penetration Testing CPENT Practice Questions (Page 7)

Part of the Web and API Penetration Testing domain, which makes up ~15% of our current practice bank.

63questions here
13free pages
16concepts

Questions 31–35

  1. 31application · medium

    During a TLS assessment, you find that the server supports TLS 1.0 and uses RC4 cipher suites. The application also has a certificate that is not trusted by major browsers. Which issue is the most critical and should be prioritized in the report?

    Select an answer first
  2. 32foundation · easy

    What is the purpose of including a risk rating in a penetration testing report?

    Select an answer first
  3. 33application · medium

    You are testing a web application protected by a WAF. Your SQL injection payload 'UNION SELECT username, password FROM users' is blocked. You try URL encoding, but it is still blocked. Which technique is most likely to bypass the WAF while still executing the SQL injection?

    Select an answer first
  4. 34application · medium

    A WAF blocks requests containing the string 'union select' in the query string. You need to test for SQL injection in a parameter that is reflected in a JSON response. Which technique is most likely to bypass the WAF while still being interpreted as a UNION-based SQL injection by the database?

    Select an answer first
  5. 35foundation · easy

    Which of the following is a primary impact of a successful cross-site scripting (XSS) attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.