Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 3Objective 2

Stored XSS WAHS Practice Questions (Page 2)

Part of the Cross-Site Scripting (XSS) domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
6concepts

Questions 6–10

  1. 6application · medium

    A security tester is mapping an application's attack surface for Stored XSS. Which of the following input points is MOST likely to be a Stored XSS injection point?

    Select an answer first
  2. 7foundation · easy

    Which testing technique is most effective for detecting a Stored XSS vulnerability in a comment field?

    Select an answer first
  3. 8foundation · easy

    Which sequence correctly describes the attack flow of Stored XSS?

    Select an answer first
  4. 9application · medium

    An attacker exploits a Stored XSS vulnerability in a company's internal wiki. The payload executes when any employee views the affected page. Which consequence is MOST likely if the payload is designed to capture keystrokes?

    Select an answer first
  5. 10expert · hard · select all that apply

    A security team is hardening a web application against Stored XSS. Which of the following controls are effective in preventing or mitigating Stored XSS? Select all that apply.

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.