
EC-CouncilWeb Application Hacking and Security
Domain 1Objective 4
API Abuse WAHS Practice Questions (Page 4)
Part of the Broken Access Control domain, which makes up ~23% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~33–55 in this domain), expect 7–11 from this objective — we provide 63 practice questions to prepare you well beyond it. (estimate)
63questions here
13free pages
14concepts
Questions 16–20
- 16
An API endpoint requires a valid JSON Web Token (JWT) to be accessed. However, any authenticated user can call the endpoint to retrieve another user's private profile data. Which security control is missing?
Select an answer first - 17
Why can deprecated API endpoints be a security risk?
Select an answer first - 18
What is a mass assignment vulnerability in the context of APIs?
Select an answer first - 19
A QA tester at a SaaS company discovers that sending a POST request to /api/v2/admin/users with a regular user's JWT successfully creates a new user with admin privileges. The endpoint is not documented in the public API reference, but it exists in the application's JavaScript bundle. Which two weaknesses combined create this vulnerability?
Select an answer first - 20
What is a common consequence of a lack of API logging and monitoring?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.