Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 5Objective 2

Web Application Firewall (WAF) and OWASP Top Ten CSE Practice Questions (Page 11)

Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.

65questions here
13free pages
16concepts

Questions 51–55

  1. 51application · medium

    A B2B integration platform accepts XML documents from partners. After a security review, the team is concerned about XXE attacks where a malicious document could read local files from the server. The WAF supports custom rules. What is the most effective WAF rule to mitigate this risk?

    Select an answer first
  2. 52foundation · easy

    In a WAF rule, what does the 'rate limiting' action typically do?

    Select an answer first
  3. 53foundation · easy

    What is a common benefit of integrating a WAF with a cloud load balancer?

    Select an answer first
  4. 54foundation · easy

    How can a WAF help detect and block broken authentication attacks?

    Select an answer first
  5. 55application · medium

    After deploying a WAF in block mode, the security team notices that legitimate users are being blocked from submitting forms that contain the word 'select' in a text field. What is the most likely cause and the best next step?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.