20+ practice questions focused on Web Application and Injection Attacks — one of the most tested topics on the Certified Ethical Hacker CEH exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Web Application and Injection Attacks PracticeAn analyst observes the following log entry on a web server: GET /../../etc/passwd HTTP/1.1 200. Which type of attack is indicated?
Explanation: The sequence '../..' in the URI path is the classic signature of directory traversal (path traversal), where an attacker uses relative path segments to escape the web root and read files outside it. The HTTP 200 response indicates /etc/passwd was successfully retrieved, confirming the traversal succeeded. This maps directly to MITRE ATT&CK T1083 (File and Directory Discovery) and OWASP A01:2021 Broken Access Control.
A web application uses user input in the following PHP code: include($_GET['page'] . '.php');. An attacker submits the URL: http://example.com/index.php?page=../../../../etc/passwd%00. Which two vulnerabilities are being attempted?
Explanation: The attacker is using '../' for directory traversal to access files outside the web root, and a null byte injection (%00) to truncate the '.php' extension. This targets LFI (local file inclusion) via directory traversal.
An attacker attempts to log into a web application by trying many common passwords for a list of known usernames. Which type of authentication attack is this?
Explanation: Password spraying involves using a few common passwords against many usernames to avoid account lockouts, as opposed to brute force (many passwords on one account) or credential stuffing (using known username/password pairs).
A web application is vulnerable to SQL injection. Which THREE of the following techniques can be used to extract data from the database using blind SQL injection?
Explanation: Time-based (A) is correct because blind SQL injection can infer data by injecting conditional delays (e.g., WAITFOR DELAY, SLEEP(), or pg_sleep()) and measuring the server's response time to determine true/false conditions. Boolean-based (C) is correct because it extracts data by sending queries that return different application responses depending on whether a condition is true or false, allowing bit-by-bit reconstruction of data without seeing query output. Out-of-band (D) is correct because it uses alternate channels such as DNS or HTTP requests (e.g., via xp_dirtree, UTL_HTTP, or LOAD_FILE) to exfiltrate data when in-band and error responses are unavailable. Error-based (B) is not marked correct because it relies on the database returning error messages containing data, which is not a blind technique. Union-based (E) is not marked correct because it requires the application to reflect query results directly in the response, which is also not blind.
A web application uses a parameter 'file' to include server-side files. The following request is intercepted: GET /page.php?file=../../../etc/passwd HTTP/1.1. The response contains the contents of /etc/passwd. This vulnerability is most likely which of the following?
Explanation: The request uses path traversal sequences (../) to access a file outside the web root. Since the application then *includes* and displays the contents of this local file (`/etc/passwd`), this is a classic example of a Local File Inclusion (LFI) vulnerability.
+15 more Web Application and Injection Attacks questions available
Practice all Web Application and Injection Attacks questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Web Application and Injection Attacks. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Web Application and Injection Attacks questions on the CEH frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Web Application and Injection Attacks is tested as part of the Certified Ethical Hacker CEH blueprint. Practicing with targeted Web Application and Injection Attacks questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CEH practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Web Application and Injection Attacks is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Web Application and Injection Attacks practice session with instant scoring and detailed explanations.
Start Web Application and Injection Attacks Practice →