
EC-CouncilWeb Application Hacking and Security
Domain 7Objective 2
Remote File Inclusion (RFI) WAHS Practice Questions (Page 4)
Part of the File Inclusion and Upload Attacks domain, which makes up ~7% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~10–17 in this domain), expect 3–6 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
5concepts
Questions 16–19
- 16
A developer is explaining RFI to a junior team member. Which statement accurately describes the mechanism of RFI?
Select an answer first - 17
Which of the following is a common way to turn an RFI vulnerability into remote code execution?
Select an answer first - 18
A penetration tester is reviewing a PHP application that loads language files using the parameter `?lang=en`. The code uses `include($_GET['lang'] . '.php');`. The tester wants to confirm RFI without causing a permanent change to the server. Which action should the tester take first?
Select an answer first - 19
A web application blocks RFI by checking if the `page` parameter starts with `http`. The check is performed after URL decoding. An attacker wants to bypass this filter. Which payload is most likely to succeed?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to WAHS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.