
EC-CouncilWeb Application Hacking and Security
Domain 2Objective 2
Command Injection WAHS Practice Questions (Page 4)
Part of the Injection Attacks domain, which makes up ~12% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
5concepts
Questions 16–20
- 16
Which of the following best describes command injection?
Select an answer first - 17
A company is migrating a legacy application to a modern framework. The application currently uses `system()` calls with user input. The migration must preserve the ability to run arbitrary system commands based on user-selected actions, but the selection must be restricted to a predefined set. Which approach is most secure?
Select an answer first - 18
Which of the following is an example of a parameter that could be vulnerable to command injection?
Select an answer first - 19
A security team is hardening a web application that uses user input to construct a command. They want to implement a defense-in-depth approach. Which combination of controls is most effective?
Select an answer first - 20
A web application has a feature that allows users to specify a filename to be processed by a server-side script. The script uses the filename in a shell command. The development team wants to fix the vulnerability without breaking the feature. Which approach is most secure and functional?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.