Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 3Objective 3

Web Application Injection Attacks GCIH Practice Questions (Page 13)

Part of the Web Application Security domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 8–13 from this objective — we provide 80 practice questions to prepare you well beyond it. (estimate)

80questions here
16free pages
25concepts

Questions 61–65

  1. 61foundation · easy

    What is the purpose of static analysis in detecting injection vulnerabilities?

    Select an answer first
  2. 62application · medium

    A Node.js application uses MongoDB and constructs a query like this: `db.users.find({ username: userInput, password: passInput })`. An attacker wants to bypass authentication. Which payload in the username field would achieve this?

    Select an answer first
  3. 63expert · hard

    A security team is testing a web application for injection vulnerabilities. They have limited time and want to identify as many injection types as possible. Which testing approach is most efficient?

    Select an answer first
  4. 64foundation · easy

    Which of the following is a secure coding practice to prevent header injection?

    Select an answer first
  5. 65foundation · easy

    What is the purpose of ASLR (Address Space Layout Randomization)?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.