Certified Ethical Hacker (CEH) Practice Question

During a web application assessment, you intercept a POST request generated by the login form. Among the submitted parameters is a hidden field named isAdmin=false that is never validated server-side in the visible code. What is the most appropriate next action to test whether authorization is enforced on the server rather than the client?

  • Run an Nmap scan against the target host to identify additional open services.

  • Place a reflected XSS payload into the isAdmin parameter to test for script execution.

  • Modify the hidden isAdmin parameter to true in the intercepted request and resend it to the server.

  • Inject a UNION-based SQL payload into the username field to attempt authentication bypass.

Certified Ethical Hacker (CEH)
Web Application Hacking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot