Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 6Objective 2

Directory Browsing and Bruteforcing WAHS Practice Questions (Page 8)

Part of the Security Misconfiguration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~19–31 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
6concepts

Questions 36–40

  1. 36application · medium

    During a web application assessment, a tester discovers that the /backup/ directory on an IIS server returns a full directory listing. The listing shows files named db_backup_2023.zip, db_backup_2024.zip, and a file called credentials.txt. What is the most immediate security concern with this finding?

    Select an answer first
  2. 37application · medium

    A security auditor is reviewing a web server and notices that requesting /assets/ returns a page listing all JavaScript and CSS files. The auditor also notices that requesting /assets/js/ returns a listing of all JavaScript files. The organization wants to keep serving these static files but prevent enumeration. Which action should the auditor recommend?

    Select an answer first
  3. 38expert · hard

    A security architect is designing a defense against brute-force attacks on a web application's login endpoint. The application is used by employees from various IP addresses, including shared office IPs. The architect wants to implement a control that minimizes the risk of locking out legitimate users while still being effective against distributed brute-force attacks. Which control is most appropriate?

    Select an answer first
  4. 39application · medium

    A web application has a login form that is vulnerable to brute force attacks. The security team wants to implement a defense that slows down automated attacks while minimizing impact on legitimate users. Which combination of controls is most effective?

    Select an answer first
  5. 40expert · medium

    A security consultant is assessing a web application hosted on a shared hosting environment. The consultant discovers that the /logs/ directory is browsable and contains application log files with sensitive information. The hosting provider does not allow changes to the main Apache configuration, but .htaccess files are permitted. The consultant must recommend a mitigation that works within these constraints. Which action is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.