
GIAC Web Application Penetration Tester
Domain 5Objective 2
Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack GWAPT Practice Questions (Page 1)
Part of the Injection and Client-Side Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 8–14 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
11concepts
Questions 1–5
- 1
A penetration tester is analyzing a web application that uses a JavaScript framework. The tester finds that user input is reflected in a JavaScript variable inside a `<script>` block. Which of the following payloads would be most likely to execute in this context?
Select an answer first - 2
Which of the following is an example of a client-side injection attack?
Select an answer first - 3
A security engineer is evaluating CSRF defenses for a web application that uses JSON-based APIs. The application currently uses a custom header (X-Requested-With) to distinguish legitimate requests. Which of the following is the most important limitation of this approach?
Select an answer first - 4
A support portal displays a user's search query in the page title and in a search-results heading. A tester submits the string `</title><script>alert(document.cookie)</script>` and observes the alert firing. The application does not use any client-side frameworks. Which classification best describes this vulnerability, and what is the most appropriate immediate fix?
Select an answer first - 5
A development team is using a modern JavaScript framework (React) to build a web application. They want to prevent client-side injection vulnerabilities. Which of the following practices is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.