
EC-CouncilWeb Application Hacking and Security
Domain 8Objective 1
Authentication Bypass WAHS Practice Questions (Page 3)
Part of the Authentication and Session Management domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~25–41 in this domain), expect 8–14 from this objective — we provide 75 practice questions to prepare you well beyond it. (estimate)
75questions here
15free pages
20concepts
Questions 11–15
- 11
How can an attacker bypass client-side authentication controls?
Select an answer first - 12
A company uses an internal identity provider (IdP) that supports OAuth 2.0 and enforces MFA. A web application integrates with this IdP for login. The application has a 'remember me' feature that issues a long-lived token. An attacker has stolen a 'remember me' token. Which of the following is the most effective mitigation to prevent the attacker from using the stolen token?
Select an answer first - 13
A legacy web application has an administrative account with the username 'admin' and password 'admin123' that was never changed after deployment. The application also allows file uploads to a directory that is accessible via the web root. Which attack chain would give an attacker persistent access?
Select an answer first - 14
How can an attacker exploit a flaw in third-party authentication to bypass authentication?
Select an answer first - 15
A web application exposes an API endpoint /api/orders/{orderId} that returns order details. The application uses a session cookie to identify the user, but it does not verify that the order belongs to the logged-in user. An attacker has a valid session and wants to view another user's order. What is the most direct attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.