Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 4Objective 2

Server-Side Request Forgery (SSRF) WAHS Practice Questions (Page 2)

Part of the Request Forgery Attacks domain, which makes up ~6% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
7concepts

Questions 6–10

  1. 6expert · hard

    A company runs a web application on Azure App Service. The application has a feature that fetches a user-supplied URL. You are concerned about SSRF targeting the Azure Instance Metadata Service (IMDS) at 169.254.169.254. You need to mitigate the risk while maintaining the feature. Which of the following is the most effective approach?

    Select an answer first
  2. 7foundation · easy

    What is the core characteristic of a Server-Side Request Forgery (SSRF) vulnerability?

    Select an answer first
  3. 8foundation · easy

    Which of the following application features is most likely to be vulnerable to SSRF?

    Select an answer first
  4. 9application · medium

    An attacker exploits an SSRF vulnerability to access the cloud metadata service. Which of the following pieces of information is the attacker most likely to obtain?

    Select an answer first
  5. 10foundation · easy

    Why is network segmentation an important defense against SSRF?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.