
EC-CouncilEthical Hacking Essentials
Domain 6Objective 2
Web Application Attack Techniques and Exploitation EHE Practice Questions (Page 10)
Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.
57questions here
12free pages
11concepts
Questions 46–50
- 46
A penetration tester is assessing a web application that uses URL-rewritten session IDs (e.g., http://example.com/page?sessionid=abc123). The tester notices that the session ID does not change after login. Which attack is most directly enabled by this behavior?
Select an answer first - 47
Which tool is specifically designed to automate the detection and exploitation of SQL injection vulnerabilities?
Select an answer first - 48
A security analyst is testing a web application's login form. The form takes a username and password, and the backend constructs a SQL query by concatenating the user input directly. The analyst wants to confirm the vulnerability without causing destructive changes. Which approach best validates the SQL injection while minimizing risk?
Select an answer first - 49
An online banking application uses cookies for session management and does not validate the Origin or Referer header on state-changing requests. A user is logged in and visits a malicious forum. Which attack could the forum use to transfer money from the user's account without the user's knowledge?
Select an answer first - 50
A developer is building a login form that accepts a username and password. The application uses a SQL database to store user credentials. Which of the following is the most secure approach to prevent SQL injection and protect passwords?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.