
EC-CouncilWeb Application Hacking and Security
Domain 6Objective 1
Security Misconfigurations WAHS Practice Questions (Page 8)
Part of the Security Misconfiguration domain, which makes up ~13% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~19–31 in this domain), expect 6–10 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
5concepts
Questions 36–40
- 36
A security engineer wants to detect misconfigurations in their web application's framework settings, such as debug mode being enabled in production, insecure cookie flags, and unnecessary HTTP methods. Which technique would be most effective for this purpose?
Select an answer first - 37
A security analyst is assessing the impact of a misconfiguration where the web application's backup files are stored in a publicly accessible directory. The backup files contain the entire database dump. Which of the following is the most severe impact?
Select an answer first - 38
A web application has an admin panel that is accessible at /admin. The application uses a default session cookie name and does not invalidate sessions after logout. An attacker steals a session cookie and gains admin access. Which misconfiguration is the root cause?
Select an answer first - 39
A security analyst is tasked with detecting misconfigurations in a database server that supports a web application. Which technique is most effective for identifying weak authentication settings?
Select an answer first - 40
An attacker exploits a misconfiguration where the web server allows the TRACE method. The attacker uses this to perform a cross-site tracing (XST) attack to steal cookies. Which misconfiguration is being exploited?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.