🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 31 minutes remaining!

Certified Ethical Hacker (CEH) Practice Question

While enumerating a target's web server, you issue an HTTP TRACE request and receive a 200 OK response that reflects all request headers back to you. From a web-server security perspective, which vulnerability does this behavior expose and what broad mitigation should you recommend to the administrator?

  • The enabled TRACE verb permits Cross-Site Tracing, so the TRACE method should be disabled or blocked in the web-server configuration.

  • It confirms that directory listing is active, so auto-indexing must be turned off.

  • It shows susceptibility to HTTP response splitting attacks, so output filtering modules must be enabled.

  • It demonstrates a server-side request forgery weakness, so stricter input validation on URL parameters is required.

Certified Ethical Hacker (CEH)
Web Application Hacking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot