You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
EC-Council's Web Application Hacking and Security (WAHS) is a hands-on specialization certification that validates your ability to play, learn, hack, test, and secure web applications against existing and emerging threats. This performance-based program challenges you with progressively difficult, Capture-The-Flag style scenarios derived from EC-Council's iLabs, covering the OWASP Top 10 and advanced attack vectors. Earning the WAHS credential proves you can perform real-world web application security assessments under pressure.
Content last reviewed 30 July 2026 · Up to date
What this certification covers, who it is written for, and what the exam itself looks like on the day.
What it validates, who it is written for, and the experience it assumes.
Beyond the written/multiple-choice exam, this certification also requires a separate hands-on lab (or practical) exam on live equipment. Practice here prepares the written qualifying exam — the lab itself needs real hands-on experience, not just study.
The EC-Council Web Application Hacking and Security (WAHS) certification is a specialization program designed for cybersecurity professionals who want to master the art of web application penetration testing. Unlike traditional knowledge-based exams, WAHS is a 100% performance-based, hands-on assessment that places you in a live, remotely proctored environment. You will be challenged with a series of progressively difficult, Capture-The-Flag (CTF) style scenarios that require you to identify, exploit, and document vulnerabilities across a broad spectrum of OWASP Top-10 attack vectors.
The program's curriculum is built on challenges derived from EC-Council's engaging iLab environments, drawing from the Certified Ethical Hacker (CEH), Certified Penetration Testing Professional (CPENT), and Certified Application Security Engineer (CASE) programs. However, WAHS goes beyond these to present more complex and realistic scenarios. You will learn by doing, with the option to follow instructor-led walkthroughs or tackle challenges independently. The exam assesses not just your understanding of automated exploitation frameworks, but also your deep understanding of web application technologies, manual exploitation techniques, and your ability to perform a security assessment in a realistic, high-pressure scenario.
Upon passing the exam, your score determines the level of certification you earn: Associate, Professional, or Expert. This tiered credentialing model allows you to prove your skills at a level that matches your proficiency, making WAHS a valuable asset for employers seeking top-tier web application security talent.
This certification is for cybersecurity and IT professionals tasked with implementing, managing, or protecting web applications. It is ideal for those who want a pure hands-on program to learn or recommend mitigation methods for a myriad of web security issues. If you are a penetration tester, application security analyst, security engineer, or a developer looking to deepen your offensive security skills, this program is designed for you. It is also well-suited for individuals who enjoy the challenge of CTF competitions and want to translate that skillset into a professional credential.
While EC-Council does not mandate specific prerequisites, a solid foundation in networking, operating systems, and basic security concepts is strongly recommended. Familiarity with penetration testing methodologies and tools will be beneficial. Understanding of core networking concepts (TCP/IP, HTTP/HTTPS); Experience with Linux operating systems and command-line interfaces; Familiarity with common web application technologies (e.g., databases, servers); Basic knowledge of penetration testing tools and methodologies
Every domain and objective EC-Council measures, with the weight they carry on the exam.
The official EC-Council exam outline · checked 30 July 2026 · See the source
Everything EC-Council publishes about sitting it, and nothing we inferred.
No mandatory prerequisites — this certification has no required predecessor exam or credential.
The path EC-Council lays out, how the credential is kept, and where to book.
Step-by-step path to EC-Council Web Application Hacking and Security
EC-Council certifications require renewal through continuing education credits. Specific renewal requirements for the WAHS certification are not detailed on the official exam page. Stay current with the latest technologies and maintain your certification.
Learn more about renewal requirementsThis certification is currently active and available. EC-Council maintains this certification to validate current skills and industry relevance.
Register for the exam through Pearson VUE, EC-Council’s authorized testing partner.
Schedule your examVisit the official EC-Council certification page for exam policies and requirements.
View the official pageYour coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.
See how the coach worksWAHS is a specialization certification. Its challenges are derived from the iLab environments of CEH and CPENT, but WAHS goes beyond these to more difficult scenarios. It is a distinct credential focused specifically on web application security.
The WAHS exam is a 100% performance-based, hands-on practical exam. It is fully online and remotely proctored, challenging candidates through a 6-hour practical assessment.
The exam is delivered through an Exam Dashboard available for 30 days from your Aspen account. You must schedule and complete the exam within this validity period. You will need a host machine with a virtual machine running your penetration testing toolkit.
The certification is designed for professionals tasked with implementing, managing, or protecting web applications, including penetration testers and application security analysts.
Yes. Your score on the exam determines your certification level: scoring more than 60% earns the Associate level, more than 75% earns the Professional level, and more than 90% earns the Expert level.
Every domain, every objective, and every concept EC-Council measures — each one written out.





Every objective below is a page you can open and practise now, without an account.
The official EC-Council exam outline · checked 30 July 2026 · See the source
In front of every objective the practice pages are already there, free and without an account. This is one objective, opened.
39 questions on this objective, five to a page. Every range above is a real page, open now, with no account.
The curriculum tells you what is on the exam. Proving you know it is a different job — and it is the one the closed-book run does.
The whole bank is open. 5 questions to a page, every answer explained, and a discussion thread on each one.
Every objective, and every page range, is a link — so you can pick up exactly where you left off.
Short enough to finish, long enough to matter.
Not only which one is right — why the others are wrong.
Ask, answer, and vote. Every question has its own thread.
These are not trivia. Each one is written against a concept in the book, so when you get one wrong there is somewhere to go and find out why.

The pages shown here come from our AI-900 book — an example of how each concept is written in plain language and, where the idea needs one, drawn as a full page you can take in at a glance.





Three reasons, and each one is a real finding rather than a slogan.
You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The whole idea at onceWhere it starts, what happens in the middle, what comes out, and the mistake to avoid.
Multimedia principle · Mayer
The look-alikes sit togetherThe pairs the exam tests are drawn side by side, so the difference is seen, not told.
Dual coding · PaivioYou are never asked to read a poster here — only to see how one is built. After that, every other page is legible at a glance.

The idea as a sequence, followed with a finger before a word is read.
What it is, how the machine learns it, when it is the right tool.
The distinction the exam tests, given its own box instead of buried in prose.
The sentence to carry into the exam room.
This is the part that teaches. The illustration and the written explanation stay where they are while you work, so a scenario stops being a memory test and becomes something you can simply look at.
A smartphone uses AI to unlock when the owner looks at the camera. Which AI capability is being used?

The same questions come back with the book closed — that run is the one that counts. After it, your coach picks one thing for tonight, sized to the time you have, and brings pages back before you lose them.
Testing effect · Roediger & Karpicke 2006 · spacing effect · Cepeda et al. 2006
Where the exam is defined, scheduled and scored.
We link to them rather than repeat them, so nothing here goes stale behind them.
We build from the official skills outline, not from a summary of it — 25 objectives, 185 concepts written under them, and free questions against every one. When EC-Council changes the outline, this page changes with it.
That is the only question worth answering the night before, and no link answers it. You answer it by taking the questions with the book closed, and seeing what comes back.