
EC-CouncilWeb Application Hacking and Security
Domain 1Objective 2
Insecure Direct Object References (IDOR) WAHS Practice Questions (Page 9)
Part of the Broken Access Control domain, which makes up ~23% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~33–55 in this domain), expect 7–11 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
Questions 41–45
- 41
An e-commerce application allows users to view their orders via /order?id=12345. A security tester finds that changing the id to another number reveals another customer's order details, including address and payment card last four digits. What is the most significant security impact of this flaw?
Select an answer first - 42
A penetration tester is testing an API that uses GUIDs for object references. The tester suspects IDOR but finds that guessing GUIDs is impractical. What is the best next step to test for IDOR?
Select an answer first - 43
A real-world IDOR incident involved a healthcare portal where patients could access other patients' medical records by changing a numeric ID in the URL. What common pattern does this illustrate?
Select an answer first - 44
A healthcare portal exposes patient records via /patient/record?id=123. A security review finds that any authenticated user can access any record by changing the id. The development team must fix this quickly. Which mitigation is most effective?
Select an answer first - 45
What is a potential security impact of an IDOR vulnerability that allows a low-privileged user to access an administrative function?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.