Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilSOC Essentials

Domain 1Objective 5

Web Application Fundamentals SCE Practice Questions (Page 8)

Part of the Computer Network and Security Fundamentals domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)

52questions here
11free pages
8concepts

Questions 36–40

  1. 36application · medium

    A user logs into a web application and closes the browser without logging out. Later, an attacker with access to the same computer opens the browser and is still authenticated. Which session management control would have prevented this?

    Select an answer first
  2. 37application · easy

    A developer is adding a feature to a web page that displays a user's name in a greeting message. The name comes from a database and is inserted into the HTML. Which client-side technology is responsible for dynamically updating the greeting without reloading the page?

    Select an answer first
  3. 38application · medium

    A web application has a search feature that reflects the user's query in the results page. A tester enters <script>alert('xss')</script> and the browser executes it. What is the most effective immediate mitigation?

    Select an answer first
  4. 39expert · hard

    A SOC analyst is investigating a series of failed login attempts to a web application. The logs show that the requests are coming from many different IP addresses, but the User-Agent string is identical. The application uses HTTPS and session cookies. Which HTTP characteristic is the analyst relying on to correlate the requests?

    Select an answer first
  5. 40expert · hard

    A web application uses cookies for session management. The security team wants to ensure that session cookies are not accessible to JavaScript and are only sent over HTTPS. Additionally, they want to prevent the cookie from being sent on cross-site requests to mitigate CSRF. Which combination of cookie attributes should be set?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.