
EC-CouncilCloud Security Essentials
Domain 5Objective 2
Web Application Firewall (WAF) and OWASP Top Ten CSE Practice Questions (Page 6)
Part of the Application Security in the Cloud domain, which makes up ~16% of our current practice bank.
65questions here
13free pages
16concepts
Questions 26–30
- 26
A development team has deployed a new web application with several debug endpoints enabled by mistake. These endpoints expose internal configuration details. The team cannot redeploy the application until the next release cycle. What WAF configuration should be used to mitigate this security misconfiguration?
Select an answer first - 27
A Java-based web application accepts serialized objects from clients. The security team is concerned about insecure deserialization attacks where a malicious object could execute arbitrary code. The application code cannot be changed immediately. What is the most effective WAF approach?
Select an answer first - 28
A company's web application has a login page that is frequently targeted by credential stuffing attacks. The security team has deployed a WAF and wants to block these attacks without blocking legitimate users who may share a corporate NAT IP. Which WAF configuration is most effective?
Select an answer first - 29
A multinational company has a web application with users in Europe and Asia. They have a strict data residency requirement that all traffic must be inspected within the region where the user is located. They also want to minimize latency. What is the best WAF deployment strategy?
Select an answer first - 30
What is a common characteristic of a Cross-Site Scripting (XSS) attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.