Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 3Objective 1

Reflected XSS WAHS Practice Questions (Page 3)

Part of the Cross-Site Scripting (XSS) domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
5concepts

Questions 11–15

  1. 11foundation · easy

    Why might an automated scanner fail to detect a reflected XSS vulnerability?

    Select an answer first
  2. 12application · medium

    A security engineer is reviewing a web application that has a 'language' parameter used to display a localized greeting. The engineer notices that the parameter is reflected in the response without encoding. The application does not store the parameter. Which type of XSS is this, and what is the primary delivery mechanism?

    Select an answer first
  3. 13application · medium

    A penetration tester is using an automated scanner to detect reflected XSS in a web application. The scanner reports a potential vulnerability in the 'q' parameter. What should the tester do to confirm the finding?

    Select an answer first
  4. 14application · medium

    An attacker wants to exploit a reflected XSS vulnerability in a banking website to steal credentials. The vulnerability is in the 'redirect' parameter, which is reflected in a JavaScript variable. Which delivery mechanism is most likely to be used?

    Select an answer first
  5. 15foundation · easy

    Which security header helps mitigate reflected XSS by preventing the browser from executing inline scripts?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.