Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 6Objective 3

Clickjacking WAHS Practice Questions (Page 2)

Part of the Security Misconfiguration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~19–31 in this domain), expect 6–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
6concepts

Questions 6–10

  1. 6application · medium

    A security analyst is using a browser extension to test a web application for clickjacking. The extension reports that the application is vulnerable because it does not send X-Frame-Options headers. What should the analyst do next to validate the finding?

    Select an answer first
  2. 7application · medium

    A web application currently uses a frame-busting script to prevent clickjacking. A security consultant notes that the script can be bypassed by using the sandbox attribute on the iframe. Which more robust defense should the consultant recommend?

    Select an answer first
  3. 8application · medium

    A security analyst is manually testing a web application for clickjacking. The analyst creates a simple HTML page with an iframe that loads the target application and opens it in a browser. The iframe displays the target application normally, and clicking inside the iframe works as expected. What does this result indicate?

    Select an answer first
  4. 9expert · hard

    A web developer is troubleshooting a clickjacking defense. The application sends the header 'Content-Security-Policy: frame-ancestors https://trusted.com' on all pages. However, when the developer tests the application by loading it in an iframe from https://trusted.com, the page does not load. The developer checks the browser console and sees an error about the frame-ancestors directive. What is the most likely cause of this issue?

    Select an answer first
  5. 10application · medium

    A penetration tester is using a browser extension to test for clickjacking. The extension allows the tester to load a target URL inside an iframe on a test page. Which additional feature would make this extension most useful for a comprehensive clickjacking assessment?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.