
GIAC Cloud Penetration Tester
Domain 5Objective 2
Web Application Attacks GCPN Practice Questions (Page 5)
Part of the Application and CI/CD Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
10concepts
Questions 21–25
- 21
A security consultant is reviewing a web application and identifies the following issues: user input is reflected in error messages without encoding, session cookies lack the HttpOnly flag, and the application does not validate the Origin header on state-changing requests. Which OWASP Top 10 categories are directly relevant to these issues? Select all that apply.
Select an answer first - 22
Which attack involves manipulating file paths to access files outside the intended directory?
Select an answer first - 23
Which of the following is a common weakness in authentication mechanisms that can be exploited by attackers?
Select an answer first - 24
A cloud-based banking application uses a session cookie that is not marked SameSite. An attacker has identified that the application's change-email endpoint accepts POST requests with only the new email address and relies on the session cookie for authentication. The attacker wants to change the victim's email address. Which attack is most directly applicable?
Select an answer first - 25
Which type of XSS vulnerability occurs when malicious script is stored on the target server, such as in a database or forum post, and then served to other users?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.