โ† All Certified Ethical Hacker Flashcard Decks

Web Application Security Flashcards

7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Web Application Security flashcards as text
  1. A JWT signed with the 'none' algorithm is dangerous because:

    Answer: It can be forged with no valid signature

    Accepting alg:none lets attackers craft tokens without a verifiable signature.

  2. Which testing approach examines a running application without source code access?

    Answer: DAST

    Dynamic Application Security Testing (DAST) probes the live app from the outside.

  3. Mass assignment vulnerabilities occur when an application:

    Answer: Binds user input directly to internal object properties

    Auto-binding request parameters to model fields can let attackers set privileged attributes.

  4. Which response best limits the impact of a successful credential-stuffing attack?

    Answer: Multi-factor authentication

    MFA requires an additional factor, blocking access even when passwords are reused or stolen.

  5. An open redirect vulnerability is commonly abused to:

    Answer: Send users to malicious sites while appearing trusted

    Open redirects forward users to attacker-controlled URLs, aiding phishing.

  6. Which practice most reduces risk from vulnerable third-party JavaScript libraries?

    Answer: Maintaining a software bill of materials and patching dependencies

    Tracking and updating dependencies addresses the Vulnerable and Outdated Components risk.

  7. Subresource Integrity (SRI) protects against:

    Answer: Tampered scripts loaded from a CDN

    SRI uses a hash to verify that fetched scripts have not been modified.