โ† All EJPT Flashcard Decks

Web Application Security & Testing Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Web Application Security & Testing flashcards as text
  1. What does the term 'stored XSS' mean in the context of web application security?

    Answer: The malicious script is persisted in the application's database and served to other users

    Stored (persistent) XSS occurs when user-supplied malicious script is saved server-side and later rendered in other users' browsers without proper encoding.

  2. Which tool is commonly used for automated directory and file brute-forcing on web servers?

    Answer: Gobuster

    Gobuster performs fast directory/file enumeration against web servers using wordlists, helping testers discover hidden endpoints and resources.

  3. During a penetration test, you find a login form that returns 'Invalid username' for nonexistent users and 'Invalid password' for valid ones. What vulnerability is this?

    Answer: Username enumeration

    Differential error messages reveal whether a username exists, allowing attackers to enumerate valid accounts before attempting password attacks.

  4. Which HTTP method, if enabled unnecessarily on a web server, can allow an attacker to upload malicious files?

    Answer: PUT

    The HTTP PUT method is designed for uploading file content to a server; if enabled without authentication, attackers can place malicious files like web shells.

  5. What is the role of a web application firewall (WAF) bypass technique during a penetration test?

    Answer: Craft payloads that evade the WAF's signature matching to reach the back-end application

    WAF bypass involves encoding, obfuscating, or fragmenting attack payloads so they are not matched by the WAF's rules while still being interpreted maliciously by the back-end.

  6. In web application testing, what is 'parameter pollution' (HPP)?

    Answer: Supplying duplicate HTTP parameters to confuse parsing logic and bypass filters

    HTTP Parameter Pollution (HPP) sends multiple values for the same parameter; inconsistent parsing between front-end and back-end can lead to filter bypass or logic flaws.

  7. Which of the following is an example of an Insecure Direct Object Reference (IDOR) vulnerability?

    Answer: Accessing another user's invoice by changing the ID in the URL from 101 to 102

    IDOR occurs when an application exposes internal object references (like database IDs) in URLs without verifying that the requesting user is authorized to access the referenced object.