Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 6Objective 2

Directory Browsing and Bruteforcing WAHS Practice Questions (Page 6)

Part of the Security Misconfiguration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~19–31 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
6concepts

Questions 26–30

  1. 26application · medium

    A security analyst is testing the resilience of a web application's REST API. The API uses a parameter 'user_id' in the URL to fetch user profiles. The analyst wants to enumerate valid user IDs by sending sequential requests. The API currently returns a 200 OK for valid IDs and a 404 Not Found for invalid ones. The analyst also notices that the API does not enforce rate limiting. Which technique is most appropriate to enumerate valid IDs efficiently?

    Select an answer first
  2. 27foundation · easy

    What is the primary purpose of using a wordlist in a directory brute force attack?

    Select an answer first
  3. 28application · medium

    During a penetration test, a tester discovers that the /logs/ directory on a web server returns a directory listing. The listing contains files named access.log, error.log, and debug.log. The tester downloads access.log and finds it contains full URLs requested by users, including query parameters. What is the most significant security impact of this finding?

    Select an answer first
  4. 29foundation · easy

    A security analyst is reviewing a web server response and notices that when requesting a directory without an index file, the server returns a page listing all files and subdirectories in that directory. What is this behavior called?

    Select an answer first
  5. 30application · medium

    A security team is reviewing the authentication mechanism of a web application. The application uses a standard username and password login. The team wants to implement a defense that makes brute force attacks significantly more difficult without requiring users to change their passwords. Which control is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.