
EC-CouncilWeb Application Hacking and Security
Domain 5Objective 3
HTTP Security Header Directives WAHS Practice Questions (Page 2)
Part of the Cryptographic Failures and Transport Security domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
10concepts
Questions 6–10
- 6
A web application has pages that contain sensitive query-string parameters (e.g., session tokens). The team wants to ensure that when users navigate to external sites, the full URL is NOT sent in the Referer header, but the origin (scheme, host, port) may be sent to internal subdomains. Which Referrer-Policy value should be set?
Select an answer first - 7
What is the purpose of the X-Content-Type-Options header?
Select an answer first - 8
A development team is configuring security headers for a new application. They want to implement a defense-in-depth approach against XSS and MIME sniffing. Which combination of headers should they apply globally to all responses?
Select an answer first - 9
A security engineer is hardening a legacy web application that has many inline event handlers (e.g., onclick) and uses a third-party CDN for jQuery. The team wants to implement CSP to reduce XSS risk, but they cannot refactor the inline handlers immediately. Which CSP strategy best balances security and functionality?
Select an answer first - 10
A security team is implementing CSP for a large legacy application that heavily uses inline event handlers (e.g., onclick attributes) and inline styles. They want to reduce XSS risk but cannot refactor the code immediately. Which CSP strategy is the most appropriate for a gradual migration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.