
GIAC Certified Incident Handler
Domain 3Objective 3
Web Application Injection Attacks GCIH Practice Questions (Page 16)
Part of the Web Application Security domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 8–13 from this objective — we provide 80 practice questions to prepare you well beyond it. (estimate)
80questions here
16free pages
25concepts
Questions 76–80
- 76
Why should user input be restricted to a small set of allowed header fields?
Select an answer first - 77
What is XPath injection?
Select an answer first - 78
A security team is hardening an application that uses XPath queries. They want to prevent XPath injection. Which mitigation is most effective?
Select an answer first - 79
Which of the following is an example of an ORM injection vulnerability?
Select an answer first - 80
A web application has a login form that builds a SQL query by concatenating the username and password fields directly into the WHERE clause. During a penetration test, an analyst submits the following as the username: ' OR '1'='1' -- and any password. The analyst successfully logs in as the first user in the database. Which remediation would most directly prevent this specific bypass while preserving the application's functionality?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCIH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.