
EC-CouncilEthical Hacking Essentials
Domain 6Objective 2
Web Application Attack Techniques and Exploitation EHE Practice Questions (Page 12)
Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.
57questions here
12free pages
11concepts
Questions 56–57
- 56
An attacker sends a link to a victim that sets the victim's session ID to a known value before the victim logs in. After login, the attacker uses that same session ID to impersonate the victim. This is an example of:
Select an answer first - 57
A penetration tester is assessing a web application that uses a WAF. The WAF blocks common SQL injection patterns like 'OR 1=1' and 'UNION SELECT'. The tester wants to bypass the WAF and confirm SQL injection in the 'id' parameter. Which technique is most likely to succeed?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to EHE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.