
EC-CouncilWeb Application Hacking and Security
Domain 1Objective 2
Insecure Direct Object References (IDOR) WAHS Practice Questions (Page 10)
Part of the Broken Access Control domain, which makes up ~23% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~33–55 in this domain), expect 7–11 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
Questions 46–49
- 46
A penetration tester is assessing a web application that uses sequential numeric IDs for user profiles. The tester wants to systematically identify IDOR vulnerabilities across multiple endpoints. Which testing approach is most effective for this purpose?
Select an answer first - 47
A well-known social media platform experienced a data breach where attackers accessed private photos of celebrities by changing the numeric photo ID in the URL. The platform had authentication but lacked authorization checks. What is the key lesson from this real-world case?
Select an answer first - 48
An attacker discovers that by changing the 'order_id' in a POST request to /api/orders/cancel, they can cancel other users' orders. The application does not verify that the order belongs to the authenticated user. What is the most likely impact of this IDOR exploitation?
Select an answer first - 49
A penetration tester is testing a web application that uses both numeric and GUID-based object references. The tester has limited time and must prioritize testing for IDOR. Which approach is most efficient?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to WAHS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.