
EC-CouncilWeb Application Hacking and Security
Domain 3Objective 1
Reflected XSS WAHS Practice Questions (Page 6)
Part of the Cross-Site Scripting (XSS) domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
5concepts
Questions 26–30
- 26
Which statement best defines reflected XSS?
Select an answer first - 27
A security analyst is comparing the risk of reflected XSS versus stored XSS in a web application. The application has a search function that reflects queries and a comment section that stores user input. Both are vulnerable. Which statement correctly compares the risk and exploitation of these two vulnerabilities?
Select an answer first - 28
An attacker crafts a URL that contains a malicious script in a parameter. The attacker sends this link to a victim via email. When the victim clicks the link, the script executes in the victim's browser and sends the victim's session cookie to the attacker's server. Which step in the attack flow is the attacker primarily exploiting?
Select an answer first - 29
A development team is fixing a reflected XSS vulnerability in a legacy application. The application uses server-side rendering and reflects user input in HTML attributes. Which defense-in-depth approach is most appropriate?
Select an answer first - 30
A penetration tester is assessing a web application that uses HttpOnly cookies for session management. The tester finds a reflected XSS vulnerability. Which impact is most likely to be achieved despite the HttpOnly flag?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.