Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 1Objective 5

CORS Misconfiguration WAHS Practice Questions (Page 3)

Part of the Broken Access Control domain, which makes up ~23% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~33–55 in this domain), expect 7–11 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
6concepts

Questions 11–15

  1. 11expert · hard

    A security engineer is reviewing a CORS misconfiguration in a banking application. The API reflects any Origin header and sets Access-Control-Allow-Credentials to true. The application also uses a CSRF token in a custom header for state-changing requests. Which statement best describes the additional risk posed by the CORS misconfiguration beyond standard CSRF defenses?

    Select an answer first
  2. 12application · medium

    A security review found that a web application's API responds to requests with Origin: null by setting Access-Control-Allow-Origin: null and Access-Control-Allow-Credentials: true. Which attack scenario is most directly enabled by this misconfiguration?

    Select an answer first
  3. 13expert · hard

    A penetration tester is evaluating a CORS misconfiguration on an API that reflects any Origin and allows credentials. The API also requires a CSRF token in a custom header for state-changing requests. The tester wants to read the victim's data via a GET request. Which statement is true?

    Select an answer first
  4. 14expert · hard

    A developer is implementing CORS for an API that is accessed by a mobile app and a web application. The web application is served from https://app.example.com. The developer wants to allow the mobile app (which does not send an Origin header) and the web app. Which configuration is correct?

    Select an answer first
  5. 15application · medium

    A security team is assessing the impact of a CORS misconfiguration on an internal HR portal. The portal uses cookie-based authentication and is accessible only from the corporate network. An attacker cannot directly access the portal, but can host a public website. Which statement best describes the risk?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.