
EC-CouncilSOC Essentials
Domain 1Objective 5
Web Application Fundamentals SCE Practice Questions (Page 9)
Part of the Computer Network and Security Fundamentals domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
8concepts
Questions 41–45
- 41
In the HTTP request-response model, which component is responsible for initiating communication with a web server?
Select an answer first - 42
What is the primary purpose of a session ID stored in a cookie?
Select an answer first - 43
A mobile app needs to authenticate users against a web service. The service exposes a RESTful API that returns a token after successful login. Which HTTP method and data format should the app use to send the login credentials?
Select an answer first - 44
A web application allows users to transfer money. An attacker crafts a malicious page that, when visited by an authenticated user, automatically submits a form to the bank's website to transfer funds. The bank's application does not verify the origin of the request. Which vulnerability is being exploited?
Select an answer first - 45
What is the primary role of a server-side web framework (e.g., Express.js, Django, Ruby on Rails)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “SCE” is a trademark of its owner, used for identification only.