Web Application Security Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Web Application Security flashcards as text
Which attack abuses XML parsers that process external entity references?
Answer: XXE
XML External Entity (XXE) attacks exploit insecure XML parsers to read files or reach internal systems.
DOM-based XSS differs from reflected XSS because the payload is processed:
Answer: Entirely in the client-side JavaScript
DOM-based XSS executes when client-side scripts write untrusted data into the DOM.
Session fixation is best prevented by:
Answer: Regenerating the session ID after login
Issuing a new session ID upon authentication stops attackers from reusing a fixed one.
Which command injection payload separator could chain an extra OS command?
Answer: ; or |
Shell metacharacters like semicolon or pipe let attackers append additional commands.
What does the SameSite cookie attribute primarily defend against?
Answer: CSRF
SameSite restricts cookies on cross-site requests, mitigating CSRF.
An attacker enumerates valid usernames by observing different error messages. This is a flaw in:
Answer: Username enumeration / verbose feedback
Distinct responses for valid vs invalid users leak account existence (username enumeration).
Which header instructs browsers to enforce HTTPS for future visits?
Answer: Strict-Transport-Security
HSTS (Strict-Transport-Security) forces browsers to use HTTPS, preventing downgrade attacks.