
EC-CouncilWeb Application Hacking and Security
Domain 1Objective 5
CORS Misconfiguration WAHS Practice Questions (Page 3)
Part of the Broken Access Control domain, which makes up ~23% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~33–55 in this domain), expect 7–11 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
6concepts
Questions 11–15
- 11
A security engineer is reviewing a CORS misconfiguration in a banking application. The API reflects any Origin header and sets Access-Control-Allow-Credentials to true. The application also uses a CSRF token in a custom header for state-changing requests. Which statement best describes the additional risk posed by the CORS misconfiguration beyond standard CSRF defenses?
Select an answer first - 12
A security review found that a web application's API responds to requests with Origin: null by setting Access-Control-Allow-Origin: null and Access-Control-Allow-Credentials: true. Which attack scenario is most directly enabled by this misconfiguration?
Select an answer first - 13
A penetration tester is evaluating a CORS misconfiguration on an API that reflects any Origin and allows credentials. The API also requires a CSRF token in a custom header for state-changing requests. The tester wants to read the victim's data via a GET request. Which statement is true?
Select an answer first - 14
A developer is implementing CORS for an API that is accessed by a mobile app and a web application. The web application is served from https://app.example.com. The developer wants to allow the mobile app (which does not send an Origin header) and the web app. Which configuration is correct?
Select an answer first - 15
A security team is assessing the impact of a CORS misconfiguration on an internal HR portal. The portal uses cookie-based authentication and is accessible only from the corporate network. An attacker cannot directly access the portal, but can host a public website. Which statement best describes the risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.