
EC-CouncilEthical Hacking Essentials
Domain 6Objective 2
Web Application Attack Techniques and Exploitation EHE Practice Questions (Page 2)
Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.
57questions here
12free pages
11concepts
Questions 6–10
- 6
Which of the following tools is commonly used as an intercepting proxy to modify HTTP requests and responses during web application testing?
Select an answer first - 7
Which XSS variant occurs entirely within the browser's Document Object Model (DOM) without the server being involved in reflecting the payload?
Select an answer first - 8
A web application has a feature that lets users fetch a URL to import an image. The application runs on a server that also hosts an internal admin panel at http://192.168.1.10/admin. A tester wants to access the admin panel through the vulnerable feature. Which attack is most appropriate?
Select an answer first - 9
A security analyst discovers that a web application reflects user-supplied input in an error message without any sanitization. The analyst suspects a reflected XSS vulnerability. Which of the following is the most effective immediate countermeasure to implement?
Select an answer first - 10
A user reports that after clicking a link in an email, their profile information on a banking website was changed without their knowledge. The website uses cookies for session management and does not require re-authentication for sensitive actions. Which attack most likely occurred, and what is the most effective countermeasure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.