
EC-CouncilWeb Application Hacking and Security
Domain 1Objective 4
API Abuse WAHS Practice Questions (Page 9)
Part of the Broken Access Control domain, which makes up ~23% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~33–55 in this domain), expect 7–11 from this objective — we provide 63 practice questions to prepare you well beyond it. (estimate)
63questions here
13free pages
14concepts
Questions 41–45
- 41
A security operations team is investigating a potential BFLA attack on an API. The API logs show that a regular user repeatedly called an admin endpoint and received 200 OK responses, but the logs do not include the request body or the user's role. The team cannot determine if the attack succeeded or what data was accessed. Which improvement to logging would most directly help in future investigations?
Select an answer first - 42
A company's API is used by both a web application at https://app.example.com and a mobile app. The API currently allows any Origin header to be reflected with Access-Control-Allow-Credentials: true to support the mobile app. A security consultant warns that this is dangerous. The company wants to keep the mobile app functional. What is the best remediation?
Select an answer first - 43
Which of the following is the best defense against injection attacks in APIs?
Select an answer first - 44
During a penetration test, you are asked to map the attack surface of a REST API. You have access to the main documentation at /api/docs, but you suspect there are undocumented endpoints. Which of the following techniques is most effective for discovering hidden API endpoints and parameters?
Select an answer first - 45
Which of the following is the best practice to prevent Broken Function Level Authorization (BFLA) vulnerabilities?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.