
EC-CouncilWeb Application Hacking and Security
Domain 3Objective 2
Stored XSS WAHS Practice Questions (Page 6)
Part of the Cross-Site Scripting (XSS) domain, which makes up ~11% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
Questions 26–30
- 26
Which of the following is a common injection point for Stored XSS?
Select an answer first - 27
In a Stored XSS attack, why does the malicious script execute for every user who views the affected page?
Select an answer first - 28
When testing for Stored XSS in a user profile field, what should a tester do after submitting a payload?
Select an answer first - 29
A security architect is designing a defense-in-depth strategy for a web application that has a stored XSS vulnerability in a rich-text editor. The editor allows users to submit formatted content that is stored and rendered for other users. The architect must balance security with functionality. Which approach is most effective?
Select an answer first - 30
A security team discovers a Stored XSS vulnerability in a customer support portal. The portal is used by both customers and internal agents. The payload steals session cookies and sends them to an attacker-controlled server. Which factor makes this vulnerability especially severe?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.