Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 8Objective 1

Authentication Bypass WAHS Practice Questions (Page 2)

Part of the Authentication and Session Management domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~25–41 in this domain), expect 8–14 from this objective — we provide 75 practice questions to prepare you well beyond it. (estimate)

75questions here
15free pages
20concepts

Questions 6–10

  1. 6expert · hard

    A web application uses a session cookie that is not marked HttpOnly. An attacker exploits a cross-site scripting (XSS) vulnerability to steal the session cookie and then replays it to impersonate the victim. Which two controls would have prevented this attack?

    Select an answer first
  2. 7foundation · easy

    What is forced browsing?

    Select an answer first
  3. 8foundation · easy

    What makes a password reset token predictable?

    Select an answer first
  4. 9foundation · easy

    What is a hardcoded backdoor?

    Select an answer first
  5. 10foundation · easy

    What is the primary goal of an authentication bypass attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.