Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilEthical Hacking Essentials

Domain 6Objective 2

Web Application Attack Techniques and Exploitation EHE Practice Questions (Page 6)

Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.

57questions here
12free pages
11concepts

Questions 26–30

  1. 26foundation · easy

    An attacker submits the following input to a search field: `' OR '1'='1`. The application constructs a SQL query by concatenating the input directly. Which type of attack is this?

    Select an answer first
  2. 27application · medium

    A web application has a login form that is vulnerable to SQL injection. The developer wants to fix the vulnerability without changing the application's functionality. Which of the following is the most secure and practical solution?

    Select an answer first
  3. 28expert · hard

    A penetration tester is using OWASP ZAP to assess a web application. The tester has identified a parameter that is vulnerable to SQL injection and another that is vulnerable to XSS. The tester wants to automate the exploitation of both vulnerabilities in a single pass. Which of the following is the most appropriate approach?

    Select an answer first
  4. 29expert · hard

    A security engineer is hardening a web application that uses cookie-based sessions. The application must remain compatible with older browsers that do not support the SameSite attribute. The engineer wants to mitigate CSRF without breaking the application's cross-site navigation. Which of the following is the most effective approach?

    Select an answer first
  5. 30foundation · easy

    Which of the following is a primary risk associated with insecure file upload functionality?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.