Web Application Security Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Web Application Security flashcards as text
A JWT signed with the 'none' algorithm is dangerous because:
Answer: It can be forged with no valid signature
Accepting alg:none lets attackers craft tokens without a verifiable signature.
Which testing approach examines a running application without source code access?
Answer: DAST
Dynamic Application Security Testing (DAST) probes the live app from the outside.
Mass assignment vulnerabilities occur when an application:
Answer: Binds user input directly to internal object properties
Auto-binding request parameters to model fields can let attackers set privileged attributes.
Which response best limits the impact of a successful credential-stuffing attack?
Answer: Multi-factor authentication
MFA requires an additional factor, blocking access even when passwords are reused or stolen.
An open redirect vulnerability is commonly abused to:
Answer: Send users to malicious sites while appearing trusted
Open redirects forward users to attacker-controlled URLs, aiding phishing.
Which practice most reduces risk from vulnerable third-party JavaScript libraries?
Answer: Maintaining a software bill of materials and patching dependencies
Tracking and updating dependencies addresses the Vulnerable and Outdated Components risk.
Subresource Integrity (SRI) protects against:
Answer: Tampered scripts loaded from a CDN
SRI uses a hash to verify that fetched scripts have not been modified.