Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCloud Security Essentials

Domain 5Objective 2

Web Application Firewall (WAF) and OWASP Top Ten CSE Practice Questions (Page 12)

Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.

65questions here
13free pages
16concepts

Questions 56–60

  1. 56foundation · easy

    How can a WAF enforce access control policies?

    Select an answer first
  2. 57foundation · easy

    What is virtual patching in the context of a WAF?

    Select an answer first
  3. 58expert · hard

    A company's web application returns personal data in JSON responses. The security team wants to use a WAF to prevent sensitive data exposure, but the application also returns similar-looking data that must not be masked. Which WAF configuration is most appropriate?

    Select an answer first
  4. 59application · medium

    A healthcare portal stores patient records and recently discovered that an attacker exfiltrated data by injecting a script that read the DOM and sent cookies to an external domain. The application team cannot fix the code immediately. What WAF configuration provides the most immediate protection against this type of data theft?

    Select an answer first
  5. 60foundation · easy

    Which of the following is a common risk category in the OWASP Top Ten?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.