Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 1Objective 5

Web Application Fundamentals SCE Practice Questions (Page 11)

Part of the Computer Network and Security Fundamentals domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
8concepts

Questions 51–52

  1. 51application · medium

    A web application is vulnerable to cross-site scripting because it reflects user input without encoding. The development team wants to implement a control that prevents the browser from interpreting user input as executable code. Which control is most appropriate?

    Select an answer first
  2. 52application · medium

    A user reports that after logging into a web application, they see another user's dashboard with sensitive data. The application uses session cookies and HTTPS. The SOC analyst reviews the logs and sees that the user's session cookie was sent over an HTTP request to a third-party domain. Which vulnerability best explains this incident?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to SCE

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.