Courseiva

CEH · domain

Network and Web Application Attacks

This domain covers how attackers exploit network protocols and web application flaws, and how defenders detect and stop them. Questions use exhibits, logs, and scenario prompts to test whether you can identify an attack in progress, pick the right mitigation, and predict an exploit's outcome using standard tools and protocols.

15 questions2 easy7 medium6 hard

Focused practice

Practice Network and Web Application Attacks questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Network and Web Application Attacks

Be able to read connection and log exhibits, name the attack class, and select the control that actually stops it. The single most important thing is matching the observed evidence to the correct attack type before choosing a mitigation.

Recognizing attack signatures in netstat, Wireshark, and IDS/IPS alerts such as port 443 connection floods

Choosing encryption protocols (TLS/HTTPS, SSH, IPsec) to defeat sniffing and man-in-the-middle capture

Identifying SQL injection, XSS, and command injection payloads and their database or server outcomes

Mapping web server and application attacks to Apache, Ubuntu, and OWASP-style countermeasures

Watch out for

Common Network and Web Application Attacks exam traps

  • ▸Assuming port 443 traffic is always safe, so encrypted command-and-control or beaconing over HTTPS is missed as benign web traffic.
  • ▸Confusing SQL injection outcomes with XSS or command injection, then selecting the wrong impact such as credential theft versus database dump.
  • ▸Recommending a firewall or IDS rule when the question asks for encryption to stop sniffing, which only TLS or SSH provides.

Question index

All Network and Web Application Attacks questions (15)

Click any question to see the full explanation, or start a practice session above.

1

You are performing a web application security assessment and discover that the application uses a hidden form field named 'price' to store the product price. The price is submitted with the form and used to process payments. Which attack would allow you to purchase an item for a lower price?

Hard
2

Refer to the exhibit. A security analyst notices multiple ESTABLISHED connections on port 443 from different external IPs to the same process ID. What type of attack is most likely occurring?

Hard
3

Refer to the exhibit. A penetration tester sends a SOAP request and receives multiple user records. Which vulnerability is present?

Hard
4

You are a security analyst for a medium-sized e-commerce company. The company hosts its web application on a single server running Apache on Ubuntu. Recently, the operations team noticed that the server's CPU usage spikes to 100% every few minutes, causing the website to become unresponsive. They have ruled out hardware issues. The web server logs show repeated requests to the same URL with varying parameters, such as /product?id=1, /product?id=2, etc., all originating from a single IP address. Each request returns a 200 OK response, but the server takes several seconds to generate the page. The application uses a relational database backend with an ORM. You suspect an attack is occurring. What is the most likely attack and the best immediate course of action?

Easy
5

You are the lead security engineer for a financial technology company that hosts a critical web application on three load-balanced servers behind a reverse proxy. The application uses a REST API to process transactions. Recently, the company has experienced intermittent service outages during peak hours. Upon reviewing logs, you find that the reverse proxy is returning HTTP 503 errors for legitimate API requests, and the application servers show high CPU usage but normal memory. The network team reports no bandwidth issues. The application team claims no code changes were made. You suspect a specific type of attack is causing the outages. Which action should you take first to confirm the attack type?

Hard
6

A security analyst is reviewing a web server log and notices a large number of requests with the User-Agent string 'sqlmap/1.5.2#stable'. The requests contain various payloads in the 'id' parameter, such as '1' AND 1=1--' and '1' UNION SELECT null, version()--'. The analyst concludes that an automated SQL injection tool is being used against the application. Which type of attack is being performed?

Easy
7

A network administrator wants to prevent an attacker from using a network sniffer to capture traffic between a client and a web server. Which protocol should be enforced to encrypt all communication?

Medium
8

A penetration tester is assigned to test a web application that uses a JSON Web Token (JWT) for session management. The tester captures the token and notices it is signed with the HS256 algorithm. After several attempts to crack the signing key offline, the tester modifies the token's payload to elevate privileges and changes the 'alg' header value to 'none'. When the modified token is sent to the server, the application accepts it and grants administrative access. Which vulnerability has the tester exploited?

Medium
9

Refer to the exhibit. A penetration tester observes that the DNS server returns both internal (10.0.0.0/8) and external (203.0.113.5) IP addresses for the same domain. What is this technique called?

Medium
10

Refer to the exhibit. A security analyst captured the HTTP request and response shown. What type of vulnerability is present?

Medium
11

Refer to the exhibit. A penetration tester executed the SQL injection payload and received the response shown. What is the most likely outcome of this attack?

Hard
12

During a penetration test, you notice that a web application accepts user input and displays it directly in the browser without sanitization. Which attack is most likely to succeed?

Medium
13

As a network defender, you notice an unusually high number of incomplete TCP three-way handshakes from a single external IP to multiple internal hosts. What is the most likely attack taking place?

Hard
14

Refer to the exhibit. An analyst runs an Nmap scan and finds these services. Which known vulnerability is most likely to be successfully exploited?

Medium
15

Match each encryption algorithm to its type.

Medium

Frequently asked questions

What does the Network and Web Application Attacks domain cover on the CEH exam?
Be able to read connection and log exhibits, name the attack class, and select the control that actually stops it. The single most important thing is matching the observed evidence to the correct attack type before choosing a mitigation.
How many questions are in this domain?
This page lists all 15 Network and Web Application Attacks questions in the CEH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Network and Web Application Attacks questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ec-ceh EC-CEH network webapp attacks Practice Questions