Courseiva

CEH Web Application and Injection Attacks Practice Question

During a web application assessment, a tester notices that a page reflects the value of a query parameter directly into the HTML response body without encoding, and the reflected value executes script in the browser when the crafted link is opened. Which of the following most accurately describes this vulnerability?

⚠ Common exam trap

The trap here is conflating any script execution in the browser with stored or DOM-based XSS, when the immediate server reflection of the parameter is what determines the reflected classification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reflected cross-site scripting, because the injected script is returned in the immediate response to the crafted request.

The defining feature is that unencoded user input is reflected in the immediate HTTP response and executes in the browser, which is reflected cross-site scripting. Stored XSS would require persistence, DOM-based XSS would originate in client-side JavaScript, and CSRF concerns forged state-changing requests rather than script execution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DOM-based cross-site scripting, because the payload is processed entirely within the client-side JavaScript.

    Why it's wrong here

    DOM-based XSS arises when client-side scripts read attacker-controllable sources such as location.hash and write them to dangerous sinks like innerHTML, without the server reflecting the payload. Here the server itself reflects the value into the response body, which points to a server-side reflection rather than a purely client-side flaw.

  • ✓

    Reflected cross-site scripting, because the injected script is returned in the immediate response to the crafted request.

    Why this is correct

    Reflected XSS occurs when user input is included in the response to the same request without proper output encoding, causing the browser to execute it. The tester's observation that the parameter is echoed back and executes when the crafted link is opened is the defining characteristic of this type.

  • ✗

    Cross-site request forgery, because the crafted link causes the victim's browser to issue an unintended request.

    Why it's wrong here

    CSRF abuses a victim's authenticated session to perform state-changing actions, but it does not involve script execution in the victim's browser. The described behavior is script execution driven by unencoded reflection, which is a scripting flaw, not a request-forgery issue.

  • ✗

    Stored cross-site scripting, because the payload persists on the server and is served to other users.

    Why it's wrong here

    Stored XSS requires the payload to be saved by the application, for example in a database or comment field, and then rendered to subsequent visitors. Here the value is echoed immediately from the request without persistence, so the stored classification does not match the observed behavior.

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.