
EC-CouncilWeb Application Hacking and Security
Domain 1Objective 5
CORS Misconfiguration WAHS Practice Questions (Page 5)
Part of the Broken Access Control domain, which makes up ~23% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~33–55 in this domain), expect 7–11 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
6concepts
Questions 21–25
- 21
To exploit a CORS misconfiguration to read sensitive data from a victim's authenticated session, what must the attacker's malicious page do?
Select an answer first - 22
A web application makes a cross-origin request to an API. The browser sends an OPTIONS preflight request. Which response header is essential for the browser to allow the actual request to proceed?
Select an answer first - 23
A penetration tester finds that an API returns Access-Control-Allow-Origin: null when the Origin header is null. The API also sets Access-Control-Allow-Credentials: true. Which attack scenario is most likely to succeed?
Select an answer first - 24
A penetration tester is exploiting a CORS misconfiguration in an application that uses cookie-based authentication. The tester wants to exfiltrate the victim's data to an attacker-controlled server. Which technique is most effective?
Select an answer first - 25
A developer is implementing CORS for an API that uses session cookies. The API must be accessible from two subdomains: app.example.com and admin.example.com. Which configuration is most secure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.