Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 1Objective 3

Parameter Tampering WAHS Practice Questions (Page 1)

Part of the Broken Access Control domain, which makes up ~23% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~33–55 in this domain), expect 7–11 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
5concepts

Questions 1–5

  1. 1foundation · easy

    How can an attacker use parameter tampering to escalate privileges in a web application?

    Select an answer first
  2. 2application · medium

    A penetration tester is assessing an e-commerce application. While intercepting traffic with Burp Suite, the tester modifies the value of a hidden form field named 'discountCode' from 'WELCOME10' to 'ADMIN50' and observes that the response reflects a 50% discount. The application also accepts a 'userID' parameter in the URL to view order history. Which action best demonstrates the core vulnerability being exploited?

    Select an answer first
  3. 3application · medium

    A security tester is reviewing a web application that uses a cookie named 'sessionID' and a separate cookie named 'isAdmin' with value 'false'. The tester changes 'isAdmin' to 'true' and gains admin access. Which of the following is the most likely reason this attack succeeds?

    Select an answer first
  4. 4application · medium

    A security analyst is reviewing a web application that allows users to download files. The URL format is: https://example.com/download?file=report.pdf&user=alice. The analyst suspects that the 'user' parameter can be tampered with to access other users' files. Which parameter is most likely to be tamperable and what is the primary risk?

    Select an answer first
  5. 5foundation · easy

    An attacker modifies the 'price' parameter in a shopping cart request from '10.00' to '0.01'. What is the most likely outcome if the application is vulnerable to parameter tampering?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.