
EC-CouncilEthical Hacking Essentials
Domain 6Objective 2
Web Application Attack Techniques and Exploitation EHE Practice Questions (Page 1)
Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.
57questions here
12free pages
11concepts
Questions 1–5
- 1
An attacker submits an XML document to a web service that includes an external entity referencing a local file. The application's XML parser processes the entity and returns the file's contents. This attack is known as:
Select an answer first - 2
A web application allows users to submit a URL that the server fetches to generate a thumbnail. The application is hosted on a cloud platform with access to internal metadata services. An attacker wants to exploit SSRF to access the cloud metadata service. Which of the following is the most effective defense?
Select an answer first - 3
In a typical three-tier web application architecture, which component is primarily responsible for executing business logic and processing user requests?
Select an answer first - 4
Which of the following is a potential impact of an XXE attack?
Select an answer first - 5
Which injection attack occurs when an application passes unsanitized user input to a system shell command?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.