
EC-CouncilWeb Application Hacking and Security
Domain 7Objective 3
Arbitrary File Upload and Download WAHS Practice Questions (Page 2)
Part of the File Inclusion and Upload Attacks domain, which makes up ~7% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~10–17 in this domain), expect 3–6 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
10concepts
Questions 6–10
- 6
An attacker exploits a file download vulnerability to retrieve the application's 'config.php' file. What is the most direct impact?
Select an answer first - 7
A web application allows users to upload files to a shared drive. The upload functionality does not restrict file types. An attacker wants to use this to launch a phishing campaign. Which attack vector is most directly applicable?
Select an answer first - 8
A web application has a file download endpoint that accepts a 'file' parameter and serves files from a directory. A penetration test reveals that an attacker can retrieve the application's source code by requesting a file like 'config.php' using path traversal. What is the most likely impact of this vulnerability?
Select an answer first - 9
A penetration tester is assessing a file upload feature that only validates the Content-Type header provided by the client. The tester wants to upload a PHP web shell. Which technique would MOST likely succeed?
Select an answer first - 10
How does a path traversal attack in file downloads typically work?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.