Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 1Objective 3

Parameter Tampering WAHS Practice Questions (Page 8)

Part of the Broken Access Control domain, which makes up ~23% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~33–55 in this domain), expect 7–11 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
5concepts

Questions 36–40

  1. 36application · medium

    A developer is implementing a file download feature where the filename is passed as a parameter in the URL. Which of the following is the most secure way to handle this parameter to prevent path traversal and unauthorized file access?

    Select an answer first
  2. 37application · medium

    A penetration tester is assessing a web application that allows users to view their own invoices. The URL for viewing an invoice is https://example.com/invoice?id=12345. During the assessment, the tester changes the id parameter to 12346 and successfully views another customer's invoice. Which of the following is the most likely root cause of this vulnerability?

    Select an answer first
  3. 38expert · hard

    A company is migrating a legacy application to a new framework. The legacy application has many parameters that are vulnerable to tampering, including 'price', 'role', and 'userID'. The team wants to implement a comprehensive mitigation strategy. Which approach is the most effective and sustainable?

    Select an answer first
  4. 39application · medium

    A QA engineer is testing an e-commerce application for parameter tampering vulnerabilities. The engineer wants to check if the 'price' field in a hidden form field can be modified to change the total cost of an order. Which of the following is the most appropriate first step?

    Select an answer first
  5. 40application · medium

    A development team is fixing a parameter tampering vulnerability where users can modify a 'discount' parameter in a request to receive unauthorized discounts. Which of the following is the most effective mitigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.