
EC-CouncilEthical Hacking Essentials
Domain 6Objective 2
Web Application Attack Techniques and Exploitation EHE Practice Questions (Page 7)
Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.
57questions here
12free pages
11concepts
Questions 31–35
- 31
A development team is implementing security controls for a web application that uses a content management system (CMS). The CMS has a plugin that is vulnerable to stored XSS. The team cannot update the plugin immediately due to compatibility issues. Which of the following is the most effective temporary mitigation?
Select an answer first - 32
A web application allows users to upload documents. The developer wants to prevent malicious file uploads. Which combination of controls is most effective?
Select an answer first - 33
A malicious script is permanently stored on a website's comment section. When any user views the page, the script executes in their browser. Which type of XSS is this?
Select an answer first - 34
Which of the following best describes the goal of a CSRF attack?
Select an answer first - 35
An attacker exploits a web application's URL parameter that fetches a remote resource. The attacker changes the URL to `http://169.254.169.254/latest/meta-data/` to access cloud metadata. This is an example of:
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.