
EC-CouncilEthical Hacking Essentials
Domain 6Objective 2
Web Application Attack Techniques and Exploitation EHE Practice Questions (Page 11)
Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.
57questions here
12free pages
11concepts
Questions 51–55
- 51
A security tester is evaluating a web service that parses XML requests. The tester suspects an XXE vulnerability. Which of the following is the most reliable way to confirm the vulnerability and read a local file?
Select an answer first - 52
A company's web application allows users to reset their password by answering a security question. The application stores the answer in plaintext and does not rate-limit attempts. An attacker has obtained a list of common answers from social media. Which combination of weaknesses is being exploited?
Select an answer first - 53
A security analyst notices that a web application sets a session cookie without the 'Secure' and 'HttpOnly' flags. The application also allows session IDs to be passed in the URL. Which attack is most directly facilitated by these weaknesses, and what is the best remediation?
Select an answer first - 54
Which part of a web application's attack surface is most directly exposed to an attacker over the internet?
Select an answer first - 55
A web application allows users to upload profile pictures. The developer only checks the file extension and MIME type. An attacker uploads a file named 'avatar.php' with a GIF header and PHP code. What is the most likely impact if the server executes the file?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.