Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 3Objective 1

Reflected XSS WAHS Practice Questions (Page 1)

Part of the Cross-Site Scripting (XSS) domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
5concepts

Questions 1–5

  1. 1expert · hard

    A penetration tester is evaluating a web application that reflects the 'callback' parameter in a JSONP response. The application does not validate the callback parameter. Which attack is most likely to succeed?

    Select an answer first
  2. 2application · medium

    A web application is vulnerable to reflected XSS because it reflects user input in a JavaScript context without encoding. Which output encoding strategy is most appropriate for this context?

    Select an answer first
  3. 3expert · hard

    A security analyst is assessing the impact of a reflected XSS vulnerability in a web application that uses HttpOnly cookies. The vulnerability allows an attacker to inject arbitrary JavaScript. Which impact is most likely despite HttpOnly cookies?

    Select an answer first
  4. 4expert · hard · select all that apply

    A security analyst is testing a web application for reflected XSS. The application reflects the 'name' parameter in the response. Which of the following techniques are valid for detecting and confirming reflected XSS? Select all that apply.

    Select an answer first
  5. 5foundation · easy

    What is a key characteristic that distinguishes reflected XSS from stored XSS?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.