Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 3Objective 3

Web Application Injection Attacks GCIH Practice Questions (Page 12)

Part of the Web Application Security domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 8–13 from this objective — we provide 80 practice questions to prepare you well beyond it. (estimate)

80questions here
16free pages
25concepts

Questions 56–60

  1. 56foundation · easy

    What is the most effective way to prevent XXE attacks?

    Select an answer first
  2. 57foundation · easy

    What is a common impact of a buffer overflow vulnerability?

    Select an answer first
  3. 58application · medium

    A legacy file-conversion utility on a Linux server accepts a filename from a web form and passes it to the shell command: system("convert " . $filename . " output.pdf"). An analyst discovers that submitting a filename like "; cat /etc/passwd; #" causes the contents of /etc/passwd to appear in the response. The application must continue to accept arbitrary filenames from authenticated users. Which remediation is the most secure and practical?

    Select an answer first
  4. 59application · medium

    A web application allows users to submit a 'name' field that is used in the 'From' header of an email. An attacker submits the following input: `victim@example.com\r\nBcc: attacker@example.com`. What is the likely impact?

    Select an answer first
  5. 60foundation · easy

    What is the primary mitigation for format string vulnerabilities?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.