
EC-CouncilEthical Hacking Essentials
Domain 6Objective 2
Web Application Attack Techniques and Exploitation EHE Practice Questions (Page 5)
Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.
57questions here
12free pages
11concepts
Questions 21–25
- 21
A development team is implementing security controls for a web application that handles sensitive user data. The team wants to mitigate XSS, CSRF, and SQL injection. Which of the following is the most comprehensive set of countermeasures?
Select an answer first - 22
Which of the following is the most effective defense against SQL injection?
Select an answer first - 23
A web application allows users to view their own profile by navigating to /profile?id=123. The application only checks that the user is logged in, not that the profile belongs to them. A user changes the id to 124 and views another user's data. Which type of vulnerability is this?
Select an answer first - 24
A security administrator is reviewing the authentication mechanism of a web application. The application uses session cookies that are valid for 24 hours and are not regenerated after login. Which of the following is the most effective way to mitigate session fixation attacks?
Select an answer first - 25
What is the primary difference between SSRF and CSRF?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.