Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 5Objective 3

HTTP Security Header Directives WAHS Practice Questions (Page 3)

Part of the Cryptographic Failures and Transport Security domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
10concepts

Questions 11–15

  1. 11foundation · easy

    Which CORS header is used by the server to indicate that a specific origin is allowed to access its resources?

    Select an answer first
  2. 12application · medium

    An organization is deploying a new public web application that must always be accessed over HTTPS. They want to prevent users from ever connecting via HTTP, even on their first visit. Which configuration should they implement?

    Select an answer first
  3. 13foundation · easy

    Which HTTP security header is specifically designed to prevent clickjacking by controlling whether a page can be displayed in a frame?

    Select an answer first
  4. 14foundation · easy

    What is the purpose of the Pragma: no-cache header in HTTP responses?

    Select an answer first
  5. 15foundation · easy

    What does the 'max-age' directive in the HSTS header specify?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.