
GIAC Web Application Penetration Tester
Domain 5Objective 2
Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack GWAPT Practice Questions (Page 9)
Part of the Injection and Client-Side Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 8–14 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)
54questions here
11free pages
11concepts
Questions 41–45
- 41
An online banking application uses a session cookie with no SameSite attribute and has anti-CSRF tokens on all forms. A penetration tester finds that the token is predictable because it is derived from the session ID using a reversible algorithm. Which attack would be most feasible for an attacker to exploit this weakness?
Select an answer first - 42
A tester discovers a stored XSS vulnerability in a forum application. The application uses HttpOnly cookies for session management. Which of the following is the most significant impact the tester can demonstrate?
Select an answer first - 43
Which of the following is a common client-side injection variant?
Select an answer first - 44
A web application uses SameSite=Strict cookies to prevent CSRF. However, after deployment, users report that they are logged out when clicking links from external sites, and some legitimate cross-site workflows break. The security team wants to maintain strong CSRF protection while improving usability. Which approach should they implement?
Select an answer first - 45
A web application uses session cookies without the SameSite attribute and relies solely on a hidden anti-CSRF token in forms. During a penetration test, you discover that the token is also exposed in a URL parameter on a page that allows user-generated content. Which additional control would most effectively mitigate CSRF while preserving the application's current functionality?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.