
EC-CouncilWeb Application Hacking and Security
Domain 7Objective 3
Arbitrary File Upload and Download WAHS Practice Questions (Page 4)
Part of the File Inclusion and Upload Attacks domain, which makes up ~7% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~10–17 in this domain), expect 3–6 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
10concepts
Questions 16–20
- 16
A web application allows users to upload profile pictures without any restrictions on file type or content. What is the primary security risk of this unrestricted upload functionality?
Select an answer first - 17
Which of the following is a mitigation strategy for arbitrary file download vulnerabilities?
Select an answer first - 18
Why is client-side validation alone insufficient for preventing arbitrary file uploads?
Select an answer first - 19
What is path canonicalization in the context of mitigating arbitrary file downloads?
Select an answer first - 20
An attacker uploads a file named 'shell.php' to a vulnerable web application. What is the most likely attack vector being used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.