Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-COUNCIL

EC-Council Web Application Hacking and Security

Certified Web Application Security Tester

EC-Council's Web Application Hacking and Security (WAHS) is a hands-on specialization certification that validates your ability to play, learn, hack, test, and secure web applications against existing and emerging threats. This performance-based program challenges you with progressively difficult, Capture-The-Flag style scenarios derived from EC-Council's iLabs, covering the OWASP Top 10 and advanced attack vectors. Earning the WAHS credential proves you can perform real-world web application security assessments under pressure.

Exam formatPerformance-based, hands-on practical exam
Duration360 minutes
DeliveryPearson VUE
Passing score60% for Associate, 75% for Professional, 90% for Expert
Free questions979

Content last reviewed 30 July 2026 · Up to date

The certification

What EC-Council Web Application Hacking and Security proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

8domains
25objectives
185concepts
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

Includes a hands-on lab exam

Beyond the written/multiple-choice exam, this certification also requires a separate hands-on lab (or practical) exam on live equipment. Practice here prepares the written qualifying exam — the lab itself needs real hands-on experience, not just study.

About this certification

The EC-Council Web Application Hacking and Security (WAHS) certification is a specialization program designed for cybersecurity professionals who want to master the art of web application penetration testing. Unlike traditional knowledge-based exams, WAHS is a 100% performance-based, hands-on assessment that places you in a live, remotely proctored environment. You will be challenged with a series of progressively difficult, Capture-The-Flag (CTF) style scenarios that require you to identify, exploit, and document vulnerabilities across a broad spectrum of OWASP Top-10 attack vectors.

The program's curriculum is built on challenges derived from EC-Council's engaging iLab environments, drawing from the Certified Ethical Hacker (CEH), Certified Penetration Testing Professional (CPENT), and Certified Application Security Engineer (CASE) programs. However, WAHS goes beyond these to present more complex and realistic scenarios. You will learn by doing, with the option to follow instructor-led walkthroughs or tackle challenges independently. The exam assesses not just your understanding of automated exploitation frameworks, but also your deep understanding of web application technologies, manual exploitation techniques, and your ability to perform a security assessment in a realistic, high-pressure scenario.

Upon passing the exam, your score determines the level of certification you earn: Associate, Professional, or Expert. This tiered credentialing model allows you to prove your skills at a level that matches your proficiency, making WAHS a valuable asset for employers seeking top-tier web application security talent.

Who it’s for

This certification is for cybersecurity and IT professionals tasked with implementing, managing, or protecting web applications. It is ideal for those who want a pure hands-on program to learn or recommend mitigation methods for a myriad of web security issues. If you are a penetration tester, application security analyst, security engineer, or a developer looking to deepen your offensive security skills, this program is designed for you. It is also well-suited for individuals who enjoy the challenge of CTF competitions and want to translate that skillset into a professional credential.

Recommended experience

While EC-Council does not mandate specific prerequisites, a solid foundation in networking, operating systems, and basic security concepts is strongly recommended. Familiarity with penetration testing methodologies and tools will be beneficial. Understanding of core networking concepts (TCP/IP, HTTP/HTTPS); Experience with Linux operating systems and command-line interfaces; Familiarity with common web application technologies (e.g., databases, servers); Basic knowledge of penetration testing tools and methodologies

The syllabus

What you’ll learn

Every domain and objective EC-Council measures, with the weight they carry on the exam.

The official EC-Council exam outline · checked 30 July 2026 · See the source

Broken Access Control
  • Privilege Escalation
  • Insecure Direct Object References (IDOR)
  • Parameter Tampering
  • API Abuse
  • CORS Misconfiguration
5 objectives · 227 free questions · 47 pages
Injection Attacks
  • Advanced SQL Injection (SQLi)
  • Command Injection
  • Remote Code Execution (RCE)
3 objectives · 119 free questions · 26 pages
Cross-Site Scripting (XSS)
  • Reflected XSS
  • Stored XSS
  • DOM-based XSS
3 objectives · 107 free questions · 23 pages
Request Forgery Attacks
  • Cross-Site Request Forgery (CSRF) - GET and POST Methods
  • Server-Side Request Forgery (SSRF)
2 objectives · 60 free questions · 13 pages
Cryptographic Failures and Transport Security
  • Weak SSL/TLS Ciphers
  • Weak Cryptographic Algorithms or Protocols
  • HTTP Security Header Directives
3 objectives · 111 free questions · 23 pages
Security Misconfiguration
  • Security Misconfigurations
  • Directory Browsing and Bruteforcing
  • Clickjacking
3 objectives · 124 free questions · 26 pages
File Inclusion and Upload Attacks
  • Local File Inclusion (LFI)
  • Remote File Inclusion (RFI)
  • Arbitrary File Upload and Download
3 objectives · 66 free questions · 14 pages
Authentication and Session Management
  • Authentication Bypass
  • Session Fixation
  • Network Scanning and Reconnaissance
3 objectives · 165 free questions · 34 pages
On the day

The exam itself

Everything EC-Council publishes about sitting it, and nothing we inferred.

Prerequisites

No mandatory prerequisites — this certification has no required predecessor exam or credential.

CertificationEC-Council Web Application Hacking and Security
Exam formatPerformance-based, hands-on practical exam
Duration360 minutes
Passing score60% for Associate, 75% for Professional, 90% for Expert
DeliveryPearson VUE
LanguagesEnglish
After you pass

Where this credential goes next

The path EC-Council lays out, how the credential is kept, and where to book.

Step-by-step path to EC-Council Web Application Hacking and Security

EC-Council Web Application Hacking and Security badgeCredential earnedEC-Council Web Application Hacking and Security Certification
Renewal and maintenance

EC-Council certifications require renewal through continuing education credits. Specific renewal requirements for the WAHS certification are not detailed on the official exam page. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. EC-Council maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by EC-Council

Exam registration

Register for the exam through Pearson VUE, EC-Council’s authorized testing partner.

Schedule your exam

Visit the official EC-Council certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the WAHS exam relate to other EC-Council certifications like CEH or CPENT?

WAHS is a specialization certification. Its challenges are derived from the iLab environments of CEH and CPENT, but WAHS goes beyond these to more difficult scenarios. It is a distinct credential focused specifically on web application security.

Is the WAHS exam purely hands-on, or does it include multiple-choice questions?

The WAHS exam is a 100% performance-based, hands-on practical exam. It is fully online and remotely proctored, challenging candidates through a 6-hour practical assessment.

What is the structure of the WAHS exam environment?

The exam is delivered through an Exam Dashboard available for 30 days from your Aspen account. You must schedule and complete the exam within this validity period. You will need a host machine with a virtual machine running your penetration testing toolkit.

What job roles does the WAHS certification map to?

The certification is designed for professionals tasked with implementing, managing, or protecting web applications, including penetration testers and application security analysts.

Can I earn different levels of the WAHS certification?

Yes. Your score on the exam determines your certification level: scoring more than 60% earns the Associate level, more than 75% earns the Professional level, and more than 90% earns the Expert level.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 979 questions, free, no account needed.