
EC-CouncilWeb Application Hacking and Security
Domain 6Objective 2
Directory Browsing and Bruteforcing WAHS Practice Questions (Page 9)
Part of the Security Misconfiguration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~19–31 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 41–42
- 41
A security analyst is explaining brute force attack risks to a development team. The team has a login form that currently allows unlimited attempts. The analyst needs to explain the core reason why this is dangerous. Which statement best describes the primary risk of unlimited login attempts?
Select an answer first - 42
An attacker finds that the /images directory on a website has directory browsing enabled. Which of the following pieces of information could the attacker most likely obtain from the directory listing?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to WAHS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.