
EC-CouncilWeb Application Hacking and Security
Domain 1Objective 2
Insecure Direct Object References (IDOR) WAHS Practice Questions (Page 3)
Part of the Broken Access Control domain, which makes up ~23% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~33–55 in this domain), expect 7–11 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
Questions 11–15
- 11
What is the most effective mitigation for an IDOR vulnerability?
Select an answer first - 12
A company's web application uses sequential numeric IDs for user profiles. A security audit recommends replacing them with indirect reference maps. What is the primary benefit of this mitigation?
Select an answer first - 13
A development team is fixing an IDOR vulnerability in a REST API. They plan to add authorization checks to each endpoint. However, they are concerned about performance and code duplication. Which approach balances security and maintainability?
Select an answer first - 14
A bug bounty hunter finds an IDOR in a banking application that allows viewing other users' transaction history by changing the 'account_id' parameter. The hunter reports it as critical. Why is this considered a high-severity issue?
Select an answer first - 15
A healthcare application allows patients to view their lab results via /results?id=123. A patient discovers that by changing the id to 124, they can view another patient's lab results, including HIV test status. Which impact is most severe?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.