Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 3Objective 1

Reflected XSS WAHS Practice Questions (Page 2)

Part of the Cross-Site Scripting (XSS) domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
5concepts

Questions 6–10

  1. 6application · medium

    An attacker wants to exploit a reflected XSS vulnerability in a web application that is protected by a Web Application Firewall (WAF). The WAF blocks requests containing '<script>'. Which technique could the attacker use to bypass the WAF and deliver a payload?

    Select an answer first
  2. 7expert · hard

    A developer is fixing a reflected XSS vulnerability in an application that reflects user input in both HTML and JavaScript contexts. The team wants to minimize code changes while ensuring security. Which approach is most effective?

    Select an answer first
  3. 8expert · hard

    A security analyst is investigating a phishing campaign that uses a legitimate website's reflected XSS vulnerability. The attacker sends an email with a link to the legitimate site that includes a payload in a parameter. When the victim clicks the link, the site displays a fake login form that is actually part of the attacker's script. Which mitigation would be most effective in preventing this specific phishing technique?

    Select an answer first
  4. 9application · medium

    A developer is testing a web form that reflects the 'username' parameter in a welcome message. To confirm a reflected XSS vulnerability, which payload should be injected into the parameter?

    Select an answer first
  5. 10expert · hard

    A company is deploying a new web application and wants to prevent reflected XSS. The development team is considering using a Content Security Policy (CSP) as the primary defense. Which statement accurately describes the role of CSP in preventing reflected XSS?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.