
EC-CouncilWeb Application Hacking and Security
Domain 8Objective 1
Authentication Bypass WAHS Practice Questions (Page 15)
Part of the Authentication and Session Management domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~25–41 in this domain), expect 8–14 from this objective — we provide 75 practice questions to prepare you well beyond it. (estimate)
75questions here
15free pages
20concepts
Questions 71–75
- 71
How can an attacker maintain unauthorized access after a user logs out?
Select an answer first - 72
A password reset feature generates a 4-digit numeric token and sends it via email. The token is valid for 24 hours and the application does not limit the number of reset attempts. An attacker who knows the victim's email can brute-force the token. Which two weaknesses are being exploited?
Select an answer first - 73
A password reset flow sends a 6-digit numeric code to the user's email. The code expires after 10 minutes. The application does not rate-limit attempts. What is the most practical attack to gain access to another user's account?
Select an answer first - 74
What is a cookie replay attack?
Select an answer first - 75
What is a common vulnerability in OAuth implementations that can lead to authentication bypass?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to WAHS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.