Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 8Objective 1

Authentication Bypass WAHS Practice Questions (Page 11)

Part of the Authentication and Session Management domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~25–41 in this domain), expect 8–14 from this objective — we provide 75 practice questions to prepare you well beyond it. (estimate)

75questions here
15free pages
20concepts

Questions 51–55

  1. 51foundation · easy

    Which HTTP method is often used to bypass authentication restrictions that only apply to GET requests?

    Select an answer first
  2. 52foundation · easy

    How can an attacker exploit a weak password recovery mechanism?

    Select an answer first
  3. 53application · medium

    A web application creates a session after login, but the session ID is generated using the current timestamp and a predictable increment. An attacker knows the approximate time of a victim's login. What is the most effective attack?

    Select an answer first
  4. 54application · medium

    A user logs out of a web application, but the session cookie remains valid on the server for another 30 minutes. An attacker who has captured the session cookie can still use it to access the user's account. Which two measures should be implemented to mitigate this risk?

    Select an answer first
  5. 55application · medium

    An application sets a session cookie with the value 'user=admin; role=user'. The server trusts the cookie's role attribute to determine access. What is the most direct way to escalate privileges?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.