
EC-CouncilWeb Application Hacking and Security
Domain 1Objective 1
Privilege Escalation WAHS Practice Questions (Page 8)
Part of the Broken Access Control domain, which makes up ~23% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~33–55 in this domain), expect 7–11 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)
39questions here
8free pages
5concepts
Questions 36–39
- 36
An attacker is logged into a web application as a regular user. They modify a request parameter that contains a user ID to access another regular user's profile. Which type of privilege escalation is this?
Select an answer first - 37
A user reports that after changing their profile's 'role' parameter from 'user' to 'admin' in a hidden form field, they gained access to the admin dashboard. Which vulnerability is being exploited, and what is the most effective immediate fix?
Select an answer first - 38
A company is designing a new web application and wants to prevent privilege escalation from the start. They are considering using a centralized authorization framework. What is the primary benefit of this approach?
Select an answer first - 39
A web application has a feature that allows users to export their data as a CSV file. The export endpoint is /export?type=users. A penetration tester finds that by changing the type parameter to 'admins', they can export a list of all admin users. The application uses a role-based access control system, but the export endpoint does not check the user's role. Which of the following is the most appropriate fix?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to WAHS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.