
EC-CouncilWeb Application Hacking and Security
Domain 2Objective 2
Command Injection WAHS Practice Questions (Page 2)
Part of the Injection Attacks domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
5concepts
Questions 6–10
- 6
A security engineer is reviewing a web application that allows users to set a 'language' preference. The application passes this value to a shell command that generates a localized report. The engineer suspects command injection. Which injection point is most likely to be exploited?
Select an answer first - 7
A development team is rewriting a legacy feature that uses user-supplied filenames in a shell command to generate thumbnails. The team wants to eliminate command injection without breaking the ability to process files. Which approach is the most secure and practical?
Select an answer first - 8
A web application has a feature that sends an email using a user-supplied recipient address. The application constructs a command like `sendmail <address>`. Which of the following is the most likely injection point?
Select an answer first - 9
Which of the following characters is commonly used to chain multiple commands in a shell?
Select an answer first - 10
Which of the following is a common injection point for command injection attacks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.