
EC-CouncilWeb Application Hacking and Security
Domain 3Objective 3
DOM-based XSS WAHS Practice Questions (Page 3)
Part of the Cross-Site Scripting (XSS) domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
7concepts
Questions 11–15
- 11
A security analyst is evaluating the risk of a DOM-based XSS vulnerability in a public-facing website. The vulnerability allows an attacker to inject arbitrary JavaScript into the page. The website does not use HttpOnly cookies. Which statement best describes the most critical risk?
Select an answer first - 12
How does Content Security Policy (CSP) help mitigate DOM-based XSS?
Select an answer first - 13
What is a potential impact of DOM-based XSS in a web application that handles sensitive user data?
Select an answer first - 14
A security team is comparing two XSS vulnerabilities. Vulnerability A is a reflected XSS in a search function. Vulnerability B is a DOM-based XSS in a client-side router. Both can be triggered by a crafted URL. Which statement best describes the key difference in how they are detected and fixed?
Select an answer first - 15
A developer is reviewing a web application for DOM-based XSS. The code reads a value from document.referrer and assigns it to an element's innerHTML property. Which combination of tools and techniques would be most effective to confirm this vulnerability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.