
EC-CouncilWeb Application Hacking and Security
Domain 1Objective 4
API Abuse WAHS Practice Questions (Page 3)
Part of the Broken Access Control domain, which makes up ~23% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~33–55 in this domain), expect 7–11 from this objective — we provide 63 practice questions to prepare you well beyond it. (estimate)
63questions here
13free pages
14concepts
Questions 11–15
- 11
An attacker intercepts a request and changes the 'role' parameter from 'user' to 'admin'. The server grants admin privileges. Which vulnerability is this?
Select an answer first - 12
What is the goal of API enumeration and discovery?
Select an answer first - 13
A security analyst is tasked with mapping the attack surface of a REST API. The analyst has access to the API's Swagger documentation, a JavaScript bundle from the web app, and a list of common API paths. Which approach would most effectively discover undocumented and deprecated endpoints that might lack proper access controls?
Select an answer first - 14
What is the primary purpose of API rate limiting?
Select an answer first - 15
A developer is building a REST API and needs to decide how to handle authentication and authorization. The API will be used by a mobile app and a web app. The developer wants to ensure that only authenticated users can access certain endpoints, and that only users with the 'admin' role can access administrative endpoints. Which of the following approaches is the most secure and appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.