Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 3Objective 3

Web Application Injection Attacks GCIH Practice Questions (Page 16)

Part of the Web Application Security domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~24–40 in this domain), expect 8–13 from this objective — we provide 80 practice questions to prepare you well beyond it. (estimate)

80questions here
16free pages
25concepts

Questions 76–80

  1. 76foundation · easy

    Why should user input be restricted to a small set of allowed header fields?

    Select an answer first
  2. 77foundation · easy

    What is XPath injection?

    Select an answer first
  3. 78application · medium

    A security team is hardening an application that uses XPath queries. They want to prevent XPath injection. Which mitigation is most effective?

    Select an answer first
  4. 79foundation · easy

    Which of the following is an example of an ORM injection vulnerability?

    Select an answer first
  5. 80application · medium

    A web application has a login form that builds a SQL query by concatenating the username and password fields directly into the WHERE clause. During a penetration test, an analyst submits the following as the username: ' OR '1'='1' -- and any password. The analyst successfully logs in as the first user in the database. Which remediation would most directly prevent this specific bypass while preserving the application's functionality?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCIH

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.