
GIAC Security Essentials
Domain 3Objective 3
Web Communication Security GSEC Practice Questions (Page 2)
Part of the Cryptography and Communications domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~11–19 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
7concepts
Questions 6–10
- 6
A web application is vulnerable to cross-site scripting (XSS) because it reflects user input without proper encoding. The security team wants to implement a defense-in-depth approach. They plan to add a Content Security Policy (CSP) header. Which CSP directive is most effective in mitigating the impact of reflected XSS?
Select an answer first - 7
What is the role of a digital certificate in HTTPS?
Select an answer first - 8
A web developer is building a login system for a healthcare portal. The application sets a session cookie after authentication. The developer wants to ensure the cookie is not accessible to client-side scripts and is only sent over HTTPS. Which set of cookie attributes should be used?
Select an answer first - 9
Which cookie attribute is used to ensure a cookie is only sent over HTTPS connections?
Select an answer first - 10
What is session fixation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.