
GIAC Cloud Penetration Tester
Domain 5Objective 2
Web Application Attacks GCPN Practice Questions (Page 6)
Part of the Application and CI/CD Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
10concepts
Questions 26–29
- 26
A development team is building a web application that allows users to upload and share documents. The application is deployed on Kubernetes in a cloud environment. The team wants to mitigate the risk of stored XSS and file upload attacks. Which of the following combinations of controls is the most effective?
Select an answer first - 27
Which of the following is a common technique used to craft a CSRF attack?
Select an answer first - 28
During a penetration test, you identify a login form that appears vulnerable to SQL injection. The application is protected by a WAF that blocks requests containing 'OR 1=1'. You need to confirm the vulnerability and extract data. Which tool and technique combination is most appropriate?
Select an answer first - 29
Which type of injection attack targets NoSQL databases by manipulating query operators such as $gt or $ne?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCPN
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.