100+ Free HTB CWES Practice Questions
HTB Certified Web Exploitation Specialist (formerly CBBH) practice questions are available now; exam metadata is being verified.
A web application uses client-side JavaScript to enforce authorization (hiding admin buttons), while the server processes all requests without authorization checks. This is an example of which flaw?
Explore More Hack The Box Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: HTB CWES Exam
Practical
Exam Format
Hack The Box
7 days
Lab Access Period
Hack The Box
8/10 flags
Passing Requirement
Hack The Box
~$210
Exam Voucher Cost
HTB Academy
3 years
Certification Validity
Hack The Box
5 web apps
Exam Targets
Hack The Box
The HTB CWES (formerly CBBH) from Hack The Box is an advanced practical web exploitation certification. Over a 7-day lab period, candidates must exploit 5 web applications and capture 8 of 10 available flags, then submit a professional penetration testing report. Core technical areas: SQL injection, XSS, SSRF, XXE, LFI/RFI, command injection, file upload vulnerabilities, web API attacks (IDOR, mass assignment, JWT), and vulnerability chaining. Certification is valid 3 years. This practice test covers the theoretical knowledge — the real exam requires live web application exploitation.
Sample HTB CWES Practice Questions
Try these sample questions to test your HTB CWES exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.