โ† All Certified Ethical Hacker Flashcard Decks

Web Application Security Flashcards

7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Web Application Security flashcards as text
  1. Which OWASP Top 10 category covers broken authentication and session weaknesses?

    Answer: Identification and Authentication Failures

    Identification and Authentication Failures addresses weak login and session management.

  2. A directory traversal attack uses sequences like ../../ to:

    Answer: Access files outside the web root

    Path traversal navigates the filesystem to read files outside the intended directory.

  3. Server-Side Request Forgery (SSRF) is dangerous mainly because it can:

    Answer: Make the server request internal resources

    SSRF tricks the server into requesting internal services or cloud metadata endpoints.

  4. Which Content-Security-Policy directive helps mitigate XSS?

    Answer: script-src

    The script-src directive restricts which sources can execute scripts, reducing XSS impact.

  5. A web shell uploaded through an unrestricted file upload allows an attacker to:

    Answer: Execute commands on the server

    A web shell provides remote command execution on the compromised server.

  6. Which flag on a session cookie prevents it from being accessed by JavaScript?

    Answer: HttpOnly

    The HttpOnly flag blocks JavaScript access, mitigating cookie theft via XSS.

  7. Blind SQL injection is identified primarily by:

    Answer: Differences in true/false responses or timing

    Blind SQLi infers data from boolean response changes or time delays, without direct output.