
EC-CouncilWeb Application Hacking and Security
Domain 6Objective 1
Security Misconfigurations WAHS Practice Questions (Page 2)
Part of the Security Misconfiguration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~19–31 in this domain), expect 6–10 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
5concepts
Questions 6–10
- 6
A web application allows users to access a debug console that displays environment variables, including database credentials. The debug console is not restricted by IP address or authentication. What is the most severe impact of this misconfiguration?
Select an answer first - 7
A security auditor needs to quickly identify misconfigured HTTP headers, outdated server software, and enabled directory listing across a set of web servers. Which approach is most efficient for this task?
Select an answer first - 8
A company is hardening its web server. They want to reduce the risk of information disclosure through error messages and server headers. Which set of actions is most effective?
Select an answer first - 9
How can an attacker exploit default credentials on a web application's admin panel?
Select an answer first - 10
Which of the following tools is commonly used to automatically scan web applications for security misconfigurations?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.