
EC-CouncilEthical Hacking Essentials
Domain 6Objective 2
Web Application Attack Techniques and Exploitation EHE Practice Questions (Page 8)
Part of the Web Application Attacks and Countermeasures domain, which makes up ~9% of our current practice bank.
57questions here
12free pages
11concepts
Questions 36–40
- 36
In a CSRF attack, what is the primary reason the victim's browser automatically includes authentication credentials with the forged request?
Select an answer first - 37
A web application allows users to upload images. The development team wants to prevent malicious file uploads that could lead to remote code execution. However, the application must support a wide variety of image formats, including SVG, which can contain scripts. Which of the following is the most effective approach?
Select an answer first - 38
A web application allows users to input a URL that the server fetches to generate a preview. An attacker exploits this to access internal services. Which of the following is the most effective mitigation?
Select an answer first - 39
A web application allows users to upload profile pictures. The developer wants to prevent attackers from uploading malicious files that could lead to remote code execution. Which of the following is the most effective control?
Select an answer first - 40
A web application issues session cookies without the Secure and HttpOnly flags. A user logs in over HTTPS, but the application also serves some content over HTTP. An attacker on the same network wants to hijack the user's session. Which attack chain is most plausible?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.