Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 5Objective 3

HTTP Security Header Directives WAHS Practice Questions (Page 7)

Part of the Cryptographic Failures and Transport Security domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)

34questions here
7free pages
10concepts

Questions 31–34

  1. 31foundation · easy

    Which CSP directive is used to specify the allowed sources for JavaScript code?

    Select an answer first
  2. 32application · medium

    A web application returns sensitive financial data in JSON responses. A security review finds that these responses are being cached by shared proxy servers, which could expose the data to other users. Which set of response headers should be applied to these endpoints?

    Select an answer first
  3. 33foundation · easy

    What is the primary role of Content Security Policy (CSP) in a web application?

    Select an answer first
  4. 34expert · hard · select all that apply

    A security team is hardening a web application that handles sensitive user data. They want to implement a baseline set of security headers. Which of the following headers should be included in the baseline? (Select all that apply.)

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to WAHS

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.