← All Certified Ethical Hacker Flashcard Decks

Web Application Security Flashcards

7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Web Application Security flashcards as text
  1. An attacker injects ' OR '1'='1 into a login form and gains access. Which vulnerability is exploited?

    Answer: SQL Injection

    The injected condition always evaluates true, bypassing authentication via SQL Injection.

  2. Which HTTP response header best mitigates clickjacking attacks?

    Answer: X-Frame-Options

    X-Frame-Options controls whether a page can be framed, preventing clickjacking.

  3. A stored XSS payload is most dangerous because it:

    Answer: Executes for every user who views the data

    Stored XSS persists on the server and runs for every victim who loads the page.

  4. Which technique best prevents SQL injection in application code?

    Answer: Parameterized queries

    Parameterized (prepared) statements separate code from data, neutralizing injection.

  5. An IDOR vulnerability typically allows an attacker to:

    Answer: Access objects belonging to other users by changing an ID

    Insecure Direct Object Reference lets users access unauthorized records by manipulating identifiers.

  6. Which tool is commonly used to intercept and modify HTTP requests during web app testing?

    Answer: Burp Suite

    Burp Suite acts as a proxy to intercept, inspect, and tamper with web traffic.

  7. What is the primary defense against Cross-Site Request Forgery?

    Answer: Anti-CSRF tokens

    Unpredictable anti-CSRF tokens ensure requests originate from the legitimate application.