ALL PASS, NO FAIL!

CEH v13 Module 14: Hacking Web Applications — Free Practice Questions with Explanations

Last updated September 2026 · 10 questions · Module 14 of 20

Web application vulnerabilities from the OWASP Top 10: XSS, CSRF, command injection, authentication flaws, and WAF bypass. Exam focus: OWASP Top 10 fluency is the bar — especially XSS (reflected, stored, DOM), CSRF tokens, and input validation. Know the payload shape that proves each flaw and the fix that kills it.

⚠️ Important Disclaimer: These practice questions are original study material created by CEHStudy for educational purposes. They are NOT EC-Council exam questions and do NOT replicate the actual exam. CEHStudy is not affiliated with or endorsed by EC-Council.

Question 1: The top category in the OWASP Top 10 (2021) is:

Answer: A — Broken Access Control tops the 2021 list, followed by Cryptographic Failures and Injection.

Question 2: Stored (persistent) XSS differs from reflected XSS because it:

Answer: B — Payloads posted to comments, profiles, or forums run for all visitors — stored XSS is typically the most damaging flavor.

Question 3: DOM-based XSS executes when:

Answer: B — The tainted source (location.hash, postMessage…) flows to a sink (innerHTML, eval) entirely in the browser — often invisible to server-side WAFs.

Question 4: Context-aware output encoding is the primary mitigation for:

Answer: C — Encoding < > " ' & (and context-specific variants) before rendering neutralizes injected scripts; frameworks that auto-escape (React, Angular) help.

Question 5: Cross-Site Request Forgery is best protected against with:

Answer: B — Random per-request tokens the attacker can't read break forged requests; SameSite cookies stop cross-site sending outright.

Question 6: Clickjacking tricks users into clicking hidden elements by:

Answer: C — The user believes they clicked your button but triggered the hidden overlay — prevented by X-Frame-Options and CSP frame-ancestors.

Question 7: Broken access control vulnerabilities such as IDOR allow:

Answer: D — Without server-side ownership checks, guessing or incrementing object IDs exposes other people's data — enforce authorization on every request.

Question 8: Burp Suite and OWASP ZAP are tools for:

Answer: C — They intercept HTTP(S) traffic, manipulate requests, and run active scans for injection, XSS, and auth flaws (plus Nikto, sqlmap, Acunetix in the toolbox).

Question 9: The HttpOnly cookie flag prevents:

Answer: C — With HttpOnly set, an injected script can't exfiltrate the session cookie — combine with Secure and SameSite for full coverage.

Question 10: 'Insecure Design' in the OWASP Top 10 refers to:

Answer: A — Design-level gaps (race conditions, flawed rate limits, unsafe workflows) require rethinking requirements and threat modeling — not just patching.

Related Glossary Terms

Continue Your CEH v13 Prep

Frequently Asked Questions

How many CEH v13 Hacking Web Applications practice questions are on this page?

This page includes 10 original multiple-choice practice questions for CEH v13 Module 14 (Hacking Web Applications). Each question includes a detailed explanation of the correct answer and why the other options are wrong. The full CEHStudy question bank covers all 20 modules with 200+ questions — see the practice hub at https://cehstudy.com/ceh-practice-questions/ for every module.

What does CEH v13 Module 14 (Hacking Web Applications) cover?

Web application vulnerabilities from the OWASP Top 10: XSS, CSRF, command injection, authentication flaws, and WAF bypass. These are the same topics tested under this module on the EC-Council 312-50 exam. Pair this quiz with our free Module 14 flashcards at https://cehstudy.com/ceh-v13/module-14/ to close any gaps.

Are these real CEH exam questions?

No. Every question on CEHStudy is original study material written for exam preparation. They match the style, difficulty, and domain coverage of the actual CEH v13 exam but are not leaked or reproduced EC-Council questions.

How should I use this Hacking Web Applications quiz for exam prep?

Answer all 10 questions without peeking at explanations, then click "Show My Score". Review every explanation — especially the ones you missed — and re-test those topics with our free CEH flashcards. Aim for 80% or higher on module quizzes before scheduling the exam.

Where do I find CEH Hacking Web Applications flashcards?

Our free flashcard app covers all 20 CEH v13 modules including Module 14 (Hacking Web Applications). Visit the CEH flashcards page at https://cehstudy.com/ or the Module 14 page at https://cehstudy.com/ceh-v13/module-14/. No account or sign-up required.