Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 1Objective 3

Parameter Tampering WAHS Practice Questions (Page 5)

Part of the Broken Access Control domain, which makes up ~23% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~33–55 in this domain), expect 7–11 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
5concepts

Questions 21–25

  1. 21application · medium

    A security analyst is reviewing a web application that uses a cookie named 'sessionID' to maintain user sessions. The analyst notices that the sessionID is a sequential number. Which of the following is the most significant risk?

    Select an answer first
  2. 22foundation · easy

    Which of the following is an example of a parameter that could be tampered with to gain unauthorized access?

    Select an answer first
  3. 23application · medium

    An application uses a signed token to protect a 'userID' parameter in a URL. The token is generated server-side and appended to the URL. Which of the following best describes the purpose of this token?

    Select an answer first
  4. 24expert · hard

    A development team is designing a new feature that allows users to download files. The team wants to prevent parameter tampering that could allow users to download files they are not authorized to access. The application already uses HTTPS and has a server-side session. Which of the following is the most secure and maintainable approach?

    Select an answer first
  5. 25expert · hard

    A security team is performing a code review of a web application. They find that the application uses a 'userID' parameter in the URL to display user profiles. The application also uses a session cookie for authentication. The team wants to identify whether the application is vulnerable to parameter tampering. Which of the following code patterns would most likely indicate a vulnerability?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.