Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 6Objective 2

Web Application Attack Techniques and Exploitation EHE Practice Questions (Page 2)

Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.

57questions here
12free pages
11concepts

Questions 6–10

  1. 6foundation · easy

    Which of the following tools is commonly used as an intercepting proxy to modify HTTP requests and responses during web application testing?

    Select an answer first
  2. 7foundation · easy

    Which XSS variant occurs entirely within the browser's Document Object Model (DOM) without the server being involved in reflecting the payload?

    Select an answer first
  3. 8application · medium

    A web application has a feature that lets users fetch a URL to import an image. The application runs on a server that also hosts an internal admin panel at http://192.168.1.10/admin. A tester wants to access the admin panel through the vulnerable feature. Which attack is most appropriate?

    Select an answer first
  4. 9application · medium

    A security analyst discovers that a web application reflects user-supplied input in an error message without any sanitization. The analyst suspects a reflected XSS vulnerability. Which of the following is the most effective immediate countermeasure to implement?

    Select an answer first
  5. 10application · medium

    A user reports that after clicking a link in an email, their profile information on a banking website was changed without their knowledge. The website uses cookies for session management and does not require re-authentication for sensitive actions. Which attack most likely occurred, and what is the most effective countermeasure?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.