Web Application Security & Testing Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Web Application Security & Testing flashcards as text
Which HTTP response header helps prevent clickjacking attacks by controlling whether a browser can render a page in an iframe?
Answer: X-Frame-Options
X-Frame-Options with values DENY or SAMEORIGIN prevents the page from being embedded in iframes on other origins, mitigating clickjacking.
During a web application test, you discover that user input is reflected directly into a JavaScript variable without sanitization. What vulnerability is most likely present?
Answer: DOM-based XSS
When user input is unsafely placed into JavaScript context without encoding, DOM-based XSS can occur as the payload is processed by the browser's JavaScript engine.
What is the primary purpose of the Burp Suite Repeater module during web application testing?
Answer: Manually resend and modify individual HTTP requests
Burp Repeater lets a tester manually modify and resend individual HTTP requests to observe how the server responds to specific changes.
Which SQL injection technique retrieves data by causing the application to make DNS or HTTP requests to an attacker-controlled server?
Answer: Out-of-band injection
Out-of-band SQL injection exfiltrates data through a separate channel such as DNS lookups or HTTP requests, useful when in-band responses aren't available.
A web application stores session tokens in a cookie without the HttpOnly flag. What attack does this primarily enable?
Answer: Cookie theft via XSS
Without HttpOnly, JavaScript can read the cookie value, so a successful XSS attack can steal the session token and hijack the user's session.
When testing for Local File Inclusion (LFI), which file on a Linux system is most commonly targeted to verify the vulnerability?
Answer: /etc/passwd
/etc/passwd is world-readable on Linux and its distinctive format makes it an ideal proof-of-concept target when confirming LFI vulnerabilities.
Which of the following best describes a Server-Side Request Forgery (SSRF) vulnerability?
Answer: An attacker causes the server to make HTTP requests to arbitrary internal or external resources
SSRF tricks the server into issuing requests on the attacker's behalf, often enabling access to internal services that are otherwise unreachable from the internet.