โ† All Certified Ethical Hacker Flashcard Decks

Web Application Security Flashcards

7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Web Application Security flashcards as text
  1. Which attack abuses XML parsers that process external entity references?

    Answer: XXE

    XML External Entity (XXE) attacks exploit insecure XML parsers to read files or reach internal systems.

  2. DOM-based XSS differs from reflected XSS because the payload is processed:

    Answer: Entirely in the client-side JavaScript

    DOM-based XSS executes when client-side scripts write untrusted data into the DOM.

  3. Session fixation is best prevented by:

    Answer: Regenerating the session ID after login

    Issuing a new session ID upon authentication stops attackers from reusing a fixed one.

  4. Which command injection payload separator could chain an extra OS command?

    Answer: ; or |

    Shell metacharacters like semicolon or pipe let attackers append additional commands.

  5. What does the SameSite cookie attribute primarily defend against?

    Answer: CSRF

    SameSite restricts cookies on cross-site requests, mitigating CSRF.

  6. An attacker enumerates valid usernames by observing different error messages. This is a flaw in:

    Answer: Username enumeration / verbose feedback

    Distinct responses for valid vs invalid users leak account existence (username enumeration).

  7. Which header instructs browsers to enforce HTTPS for future visits?

    Answer: Strict-Transport-Security

    HSTS (Strict-Transport-Security) forces browsers to use HTTPS, preventing downgrade attacks.