
GIAC Security Essentials
Domain 3Objective 3
Web Communication Security GSEC Practice Questions (Page 7)
Part of the Cryptography and Communications domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~11–19 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)
46questions here
10free pages
7concepts
Questions 31–35
- 31
Which security header is used to control the sources from which a web page can load resources?
Select an answer first - 32
A web application has a strict Content Security Policy (CSP) that only allows scripts from the same origin. The application also uses a third-party analytics script that is loaded from a CDN. The security team wants to keep the CSP strict while allowing the analytics script. Which CSP directive should be modified?
Select an answer first - 33
A web application is vulnerable to clickjacking because it can be embedded in an iframe on an attacker's site. The security team wants to prevent this while still allowing the application to be embedded in a trusted partner's site. Which header configuration should be used?
Select an answer first - 34
A web application uses session cookies for authentication. The security team wants to reduce the risk of cross-site request forgery (CSRF) attacks. Which cookie attribute should be set to prevent the browser from sending the cookie with cross-site requests?
Select an answer first - 35
What is a session hijacking attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.