
EC-CouncilWeb Application Hacking and Security
Domain 3Objective 2
Stored XSS WAHS Practice Questions (Page 4)
Part of the Cross-Site Scripting (XSS) domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
Questions 16–20
- 16
A penetration tester is testing a web application for Stored XSS. They submit a unique string like `zzxss123` in a comment field and then view the comment page. What is the purpose of this action?
Select an answer first - 17
A security analyst is evaluating the impact of a stored XSS vulnerability in a web application that uses JSON Web Tokens (JWT) for authentication. The JWT is stored in a cookie that is NOT marked HttpOnly. An attacker exploits the stored XSS to steal the JWT. What is the most significant consequence?
Select an answer first - 18
How does a Content Security Policy (CSP) help mitigate Stored XSS?
Select an answer first - 19
A security analyst is explaining a Stored XSS attack to a colleague. The attack involves an attacker posting a comment, the server saving it, and then a victim viewing the comment. Which step is the 'execution' step?
Select an answer first - 20
A development team is implementing a fix for a Stored XSS vulnerability in a user-generated content feature. The feature allows users to submit HTML that is rendered to other users. The team wants to allow safe HTML while preventing script execution. Which approach is MOST robust?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.