
EC-CouncilWeb Application Hacking and Security
Domain 8Objective 1
Authentication Bypass WAHS Practice Questions (Page 7)
Part of the Authentication and Session Management domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~25–41 in this domain), expect 8–14 from this objective — we provide 75 practice questions to prepare you well beyond it. (estimate)
75questions here
15free pages
20concepts
Questions 31–35
- 31
How can an attacker bypass authentication via API endpoints?
Select an answer first - 32
How can an attacker manipulate a cookie to bypass authentication?
Select an answer first - 33
An application uses two-factor authentication (2FA) where the second factor is a 6-digit code sent via SMS. The code is valid for 10 minutes and the application does not limit the number of attempts. An attacker who has stolen the user's password can brute-force the 2FA code. Which two weaknesses are being exploited?
Select an answer first - 34
What is the best practice to prevent information leakage through error messages?
Select an answer first - 35
A web application's logout function only deletes the session cookie from the browser but does not invalidate the session on the server. An attacker who has captured a valid session ID can continue to use it. What is the flaw?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.