Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 7Objective 2

Remote File Inclusion (RFI) WAHS Practice Questions (Page 2)

Part of the File Inclusion and Upload Attacks domain, which makes up ~7% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~10–17 in this domain), expect 3–6 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)

19questions here
4free pages
5concepts

Questions 6–10

  1. 6foundation · easy

    Which of the following is the most effective remediation to prevent Remote File Inclusion vulnerabilities?

    Select an answer first
  2. 7application · medium

    A security analyst is reviewing a PHP application's source code and wants to identify parameters that could be vulnerable to RFI. Which code pattern is most indicative of an RFI vulnerability?

    Select an answer first
  3. 8application · medium

    A developer is tasked with preventing RFI in a PHP application. The application uses include($_GET['file']);. The developer proposes disabling allow_url_include. What is the main limitation of this approach?

    Select an answer first
  4. 9foundation · easy

    Which statement best describes a Remote File Inclusion (RFI) vulnerability?

    Select an answer first
  5. 10application · medium

    A company's web application was compromised via an RFI attack. The incident response team needs to prevent recurrence. Which combination of measures is most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.