Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 8Objective 1

Authentication Bypass WAHS Practice Questions (Page 10)

Part of the Authentication and Session Management domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~25–41 in this domain), expect 8–14 from this objective — we provide 75 practice questions to prepare you well beyond it. (estimate)

75questions here
15free pages
20concepts

Questions 46–50

  1. 46expert · hard

    A web application allows users to sign in with their Google account using OAuth 2.0. The application uses the 'email' claim from the Google token to identify the user but does not verify that the token was issued for its own client ID. An attacker creates a malicious OAuth application and tricks a victim into authorizing it, then uses the token to log in as the victim. Which two vulnerabilities are being exploited?

    Select an answer first
  2. 47foundation · easy

    How can an attacker use HTTP methods to bypass authentication?

    Select an answer first
  3. 48foundation · easy

    What is a common risk associated with default credentials?

    Select an answer first
  4. 49foundation · easy

    What is the most effective defense against SQL injection in authentication?

    Select an answer first
  5. 50foundation · easy

    What is client-side authentication bypass?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.