
EC-CouncilWeb Application Hacking and Security
Domain 4Objective 2
Server-Side Request Forgery (SSRF) WAHS Practice Questions (Page 4)
Part of the Request Forgery Attacks domain, which makes up ~6% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
7concepts
Questions 16–20
- 16
A web application allows users to upload an image from a URL. The application fetches the URL server-side and stores the image. An attacker discovers that they can access internal services by providing a URL like http://192.168.1.1:8080/admin. Which of the following is the most likely entry point for this SSRF?
Select an answer first - 17
A web application has a feature that allows users to upload an image from a URL. The application fetches the URL server-side. You are tasked with hardening the application against SSRF. Which of the following is the most robust defense?
Select an answer first - 18
An attacker exploits an SSRF vulnerability in a web application hosted on AWS to access the metadata service. The attacker retrieves the IAM role's temporary credentials. Which of the following is the most critical risk associated with this attack?
Select an answer first - 19
A company is deploying a web application that allows users to submit a URL for a 'link preview' feature. The application runs on a Kubernetes cluster in a cloud environment. Which of the following is the most effective SSRF mitigation strategy?
Select an answer first - 20
Which of the following protocols can be used in an SSRF attack to interact with internal services?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.