Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 1Objective 5

CORS Misconfiguration WAHS Practice Questions (Page 4)

Part of the Broken Access Control domain, which makes up ~23% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~33–55 in this domain), expect 7–11 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
6concepts

Questions 16–20

  1. 16foundation · easy

    Which statement correctly describes the relationship between the Same-Origin Policy and CORS?

    Select an answer first
  2. 17expert · hard

    A security team is evaluating the risk of a CORS misconfiguration in a public API that does not use cookies but uses a bearer token in the Authorization header. The API reflects any Origin header but does not set Access-Control-Allow-Credentials. Which statement best describes the risk?

    Select an answer first
  3. 18application · medium

    A company is migrating a legacy web application to a microservices architecture. The new API will be accessed by a React dashboard on a different subdomain. The API uses cookie-based authentication. The team wants to avoid CORS misconfigurations. Which approach is the most secure and maintainable?

    Select an answer first
  4. 19expert · hard

    A company is designing a CORS policy for a new API that will be used by multiple partner applications, each with a different subdomain of partner.example.com (e.g., app1.partner.example.com, app2.partner.example.com). The API uses cookie-based authentication. The team wants to allow all partner subdomains but no others. Which approach is the most secure and maintainable?

    Select an answer first
  5. 20expert · hard

    A security architect is reviewing a CORS configuration for a banking API. The API is accessed by a legacy partner application that sends the Origin header as null because it runs in a sandboxed iframe. The partner cannot change its application. The architect must allow this partner while preventing other null-origin attacks. What is the most secure solution?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.