
GIAC Web Application Penetration Tester
Domain 5Objective 2
Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack GWAPT Practice Questions (Page 2)
Part of the Injection and Client-Side Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 8–14 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
11concepts
Questions 6–10
- 6
A security team is implementing CSRF defenses for a high-security application. They have deployed anti-CSRF tokens and SameSite=Strict cookies. However, a penetration test reveals that the application is still vulnerable to CSRF because the token is stored in a cookie that is sent with cross-site requests. Which additional control would BEST mitigate this issue?
Select an answer first - 7
A security analyst is reviewing a web application that uses a JavaScript framework with automatic output encoding. The analyst discovers that the framework's encoding is bypassed when user input is used in a specific context, such as a JavaScript template literal. Which action would BEST address this vulnerability?
Select an answer first - 8
Which of the following payloads is an example of an XSS payload that uses an HTML event handler?
Select an answer first - 9
A development team is migrating a legacy web application to a modern framework. The legacy application has numerous client-side injection vulnerabilities. The team wants to minimize the risk while preserving existing functionality. Which approach is MOST effective?
Select an answer first - 10
Which of the following is the most effective defense against XSS when user input is reflected in an HTML context?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.