
EC-CouncilWeb Application Hacking and Security
Domain 6Objective 3
Clickjacking WAHS Practice Questions (Page 6)
Part of the Security Misconfiguration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~19–31 in this domain), expect 6–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
Questions 26–30
- 26
A penetration tester is assessing a web application for clickjacking vulnerabilities. The tester wants to use an automated tool that can quickly scan multiple pages and identify which ones are missing anti-framing headers. Which tool is most appropriate for this task?
Select an answer first - 27
A security consultant is evaluating the risk of a clickjacking vulnerability in a banking application. The application allows users to transfer funds and change their contact information. The consultant notes that the application uses session cookies with the Secure and HttpOnly flags, and it does not send any anti-framing headers. Which statement best describes the risk to users?
Select an answer first - 28
Which statement best describes how clickjacking deceives a user?
Select an answer first - 29
Which HTTP response header is specifically designed to prevent a page from being displayed in an iframe?
Select an answer first - 30
An online retailer's checkout page is vulnerable to clickjacking. An attacker creates a malicious site that frames the checkout page and tricks users into clicking the 'Place Order' button. What is the most likely impact on the user?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.