
EC-CouncilWeb Application Hacking and Security
Domain 5Objective 3
HTTP Security Header Directives WAHS Practice Questions (Page 7)
Part of the Cryptographic Failures and Transport Security domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
10concepts
Questions 31–34
- 31
Which CSP directive is used to specify the allowed sources for JavaScript code?
Select an answer first - 32
A web application returns sensitive financial data in JSON responses. A security review finds that these responses are being cached by shared proxy servers, which could expose the data to other users. Which set of response headers should be applied to these endpoints?
Select an answer first - 33
What is the primary role of Content Security Policy (CSP) in a web application?
Select an answer first - 34
A security team is hardening a web application that handles sensitive user data. They want to implement a baseline set of security headers. Which of the following headers should be included in the baseline? (Select all that apply.)
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to WAHS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.