
EC-CouncilWeb Application Hacking and Security
Domain 6Objective 3
Clickjacking WAHS Practice Questions (Page 1)
Part of the Security Misconfiguration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~19–31 in this domain), expect 6–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
Questions 1–5
- 1
A web application is deployed behind a CDN that strips unknown HTTP headers. The security team wants to implement clickjacking protection. Which approach will work reliably in this environment?
Select an answer first - 2
Which Content Security Policy directive is used to control which origins are allowed to embed a page in an iframe?
Select an answer first - 3
What is a potential impact of a successful clickjacking attack on a web application?
Select an answer first - 4
A developer is implementing clickjacking defenses for a web application. The application must support older browsers that do not recognize the CSP frame-ancestors directive. Which defense should the developer implement to ensure protection across all supported browsers?
Select an answer first - 5
A web application's security team is implementing clickjacking defenses. They need to protect a critical admin panel that should only be embeddable by the same origin, while also providing a fallback for older browsers that do not support CSP. Which combination of headers should they send?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.