← All EJPT Flashcard Decks

Web Application Penetration Testing Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Web Application Penetration Testing flashcards as text
  1. What is the difference between a 'whitebox' and 'blackbox' web application penetration test?

    Answer: Whitebox provides the tester with source code and architecture details; blackbox gives no prior knowledge

    In a whitebox test the tester has full knowledge (source code, diagrams, credentials), while a blackbox test simulates an external attacker with zero prior information.

  2. Which Burp Suite feature allows you to send a request to multiple payloads automatically, cycling through a wordlist?

    Answer: Burp Intruder

    Burp Intruder automates customized attacks by injecting payloads from a wordlist into marked positions within a request.

  3. What does the term 'parameter tampering' mean in web application security testing?

    Answer: Intercepting and modifying HTTP parameters to alter application logic or access unauthorized data

    Parameter tampering involves modifying HTTP parameters (query strings, form fields, cookies) to manipulate application behavior in ways the developer did not intend.

  4. You discover a web application that makes server-side HTTP requests to URLs specified by user input. Which vulnerability is this?

    Answer: Server-Side Request Forgery (SSRF)

    SSRF occurs when a server makes HTTP requests to attacker-controlled URLs, potentially allowing access to internal services or cloud metadata endpoints.

  5. Which HTTP status code typically indicates that a resource exists but the user is not authorized to view it, which can be useful during enumeration?

    Answer: 403 Forbidden

    A 403 Forbidden response confirms the resource exists but access is denied, whereas 404 would suggest the resource doesn't exist — making 403 useful for confirming valid paths.

  6. What is the primary risk of an 'Insecure Direct Object Reference' (IDOR) vulnerability?

    Answer: Accessing or modifying other users' data by manipulating object identifiers

    IDOR allows attackers to access unauthorized resources (other users' files, records, accounts) simply by modifying an object reference like a user ID in a URL or request.

  7. Which tool is commonly used for directory and file enumeration against web servers during a penetration test?

    Answer: Gobuster

    Gobuster is a fast brute-force tool used to enumerate hidden directories, files, and DNS subdomains by sending HTTP requests using a wordlist.