Courseiva

CEH · topic practice

Web Application and Injection Attacks practice questions

This CEH domain covers how attackers exploit web applications and backend databases, and how defenders stop them. Questions test recognition of attack types from scenario descriptions, matching mitigations to specific vulnerabilities, and identifying the tools and techniques used to find and exploit injection flaws in real assessments.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Web Application and Injection Attacks

What the exam tests

What to know about Web Application and Injection Attacks

Be able to read a web attack scenario and name the attack, then match the correct mitigation to the vulnerability. The single most important thing: distinguish credential stuffing from brute force, and pair CSRF with tokens or SameSite cookies, not CAPTCHA.

Credential stuffing versus brute force when a login form permits unlimited attempts

CSRF defenses such as anti-CSRF tokens and SameSite cookie attributes

SQL injection discovery and exploitation using sqlmap and manual payloads

Injection classes including SQL, command, and cross-site scripting in web forms

Watch out for

Common Web Application and Injection Attacks exam traps

  • ▸Confusing credential stuffing with brute force: stuffing reuses breached username/password pairs, while brute force guesses credentials without a prior breach list.
  • ▸Choosing CAPTCHA or account lockout as the CSRF answer; those stop brute force, not forged requests from an authenticated browser.
  • ▸Assuming any scanner finds SQL injection; sqlmap is the tool named for automating SQLi detection and exploitation.

Practice set

Web Application and Injection Attacks questions

20 questions · select your answer, then reveal the explanation

An analyst observes the following log entry on a web server: GET /../../etc/passwd HTTP/1.1 200. Which type of attack is indicated?

A web application uses user input in the following PHP code: include($_GET['page'] . '.php');. An attacker submits the URL: http://example.com/index.php?page=../../../../etc/passwd%00. Which two vulnerabilities are being attempted?

An attacker attempts to log into a web application by trying many common passwords for a list of known usernames. Which type of authentication attack is this?

A web application is vulnerable to SQL injection. Which THREE of the following techniques can be used to extract data from the database using blind SQL injection?

A web application uses a parameter 'file' to include server-side files. The following request is intercepted: GET /page.php?file=../../../etc/passwd HTTP/1.1. The response contains the contents of /etc/passwd. This vulnerability is most likely which of the following?

Which THREE of the following are common indicators of an ongoing brute-force attack against a web application?

During a penetration test, a tester uses SQLMap with the following command: 'sqlmap -u "http://target.com/page?id=1" --os-shell'. The target is a Linux server running MySQL. Which SQL injection technique will SQLMap likely attempt to use to achieve an OS shell?

Which OWASP Top 10 (2021) category describes the vulnerability where an application allows an attacker to include a remote file from an external server, leading to code execution or data disclosure?

A security analyst identifies a vulnerability where an attacker can include a local file such as '/etc/passwd' by manipulating the 'page' parameter in the URL: http://example.com/index.php?page=../../../../etc/passwd. What type of attack is this?

During a security assessment, a tester discovers an endpoint that reflects the 'User-Agent' header in the response without sanitization. The tester wants to confirm a reflected XSS vulnerability. Which of the following payloads would be MOST effective to demonstrate the issue in a single request?

An application uses the SameSite cookie attribute. Which THREE of the following are valid values for this attribute and their purposes? (Select three)

Which TWO of the following are common indicators of a command injection vulnerability? (Select 2)

Which of the following is a primary defense mechanism against Cross-Site Request Forgery (CSRF) attacks?

A penetration tester is assessing a web application and wants to manually test for SQL injection vulnerabilities. Which TWO tools or techniques are best suited for this task?

Which TWO of the following are common types of SQL injection attacks?

During a web application penetration test, a tester uses Burp Suite's Intruder tool to automate a series of login attempts using a list of common passwords. Which attack type is being performed?

An attacker exploits an application by uploading a file that contains server-side script code, leading to arbitrary command execution on the web server. Which best describes this attack?

Which TWO of the following are common methods to detect SQL injection vulnerabilities in a web application? (Select 2)

A pentester uses Burp Suite's Intruder to perform a brute-force attack on a login form. Which TWO of the following Intruder attack types would be appropriate for testing different payload combinations?

A web application uses cookies for session management. The application is vulnerable to CSRF. Which THREE of the following are effective mitigation techniques? (Choose THREE.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Web Application and Injection Attacks sessions

Start a Web Application and Injection Attacks only practice session

Every question in these sessions is drawn from the Web Application and Injection Attacks domain — nothing else.

Related practice questions

Related CEH topic practice pages

Move into related areas when this topic feels solid.

Scanning Networks and Enumeration practice questions

Scanning Networks and Enumeration practice questions for CEH.

Wireless, IoT and Cloud Security practice questions

Wireless, IoT and Cloud Security practice questions for CEH.

Vulnerability Analysis and System Hacking practice questions

Practise CEH questions linked to Vulnerability Analysis and System Hacking.

Advanced Topics: Wireless, Cloud, IoT, Cryptography practice questions

Sharpen your CEH knowledge of Advanced Topics: Wireless, Cloud, IoT, Cryptography.

Cryptography and Malware Analysis practice questions

Targeted CEH practice covering Cryptography and Malware Analysis.

Footprinting and Reconnaissance practice questions

Targeted CEH practice covering Footprinting and Reconnaissance.

Network and Web Application Attacks practice questions

Targeted CEH practice covering Network and Web Application Attacks.

Enumeration and System Hacking practice questions

Practise CEH questions linked to Enumeration and System Hacking.

Footprinting, Reconnaissance and Scanning practice questions

Sharpen your CEH knowledge of Footprinting, Reconnaissance and Scanning.

Social Engineering and Physical Security practice questions

Practise CEH questions linked to Social Engineering and Physical Security.

Malware, Social Engineering and Network Attacks practice questions

Sharpen your CEH knowledge of Malware, Social Engineering and Network Attacks.

Web Application and Injection Attacks practice questions

Sharpen your CEH knowledge of Web Application and Injection Attacks.

Frequently asked questions

What does the CEH exam test about Web Application and Injection Attacks?
Be able to read a web attack scenario and name the attack, then match the correct mitigation to the vulnerability. The single most important thing: distinguish credential stuffing from brute force, and pair CSRF with tokens or SameSite cookies, not CAPTCHA.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Web Application and Injection Attacks questions in a focused session?
Yes — the session launcher on this page draws every question from the Web Application and Injection Attacks domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CEH topics?
Use the topic links above to move to related areas, or go back to the CEH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CEH exam covers. They are not copied from any real exam or dump site.