Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Essentials

Domain 3Objective 3

Web Communication Security GSEC Practice Questions (Page 1)

Part of the Cryptography and Communications domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~11–19 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
7concepts

Questions 1–5

  1. 1expert · hard

    A company runs a web application behind a web application firewall (WAF). The WAF is blocking a legitimate user who is submitting a form with a long text field that contains special characters. The user's request is being flagged as a potential SQL injection. The application team confirms the input is properly parameterized and safe. What is the best way to handle this false positive?

    Select an answer first
  2. 2application · medium

    A web administrator is configuring a new server for a public website. The administrator wants to ensure that the server only supports strong cipher suites and that the certificate chain is complete. Which action is most important for ensuring the server's TLS configuration is secure?

    Select an answer first
  3. 3application · medium

    A web developer is implementing session management for a banking application. The security team requires that session tokens cannot be stolen via cross-site scripting (XSS) and that the session cannot be hijacked by an attacker who captures the token over the network. Which two cookie attributes should be set on the session cookie?

    Select an answer first
  4. 4application · medium

    A small e-commerce company recently deployed a new web application. Customers are reporting that their browsers show a warning when they visit the site, and some refuse to proceed. The site is hosted on a single server with a public IP. The administrator checks the certificate and finds it is self-signed. What is the most likely cause of the browser warning, and what should the administrator do to resolve it?

    Select an answer first
  5. 5expert · hard

    A security analyst is reviewing the TLS configuration of a web server. The server supports TLS 1.2 and 1.3, but the analyst notices that the server allows renegotiation. The analyst is concerned about a potential renegotiation attack. Which action should the analyst take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.