Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Web Application Penetration Tester

Domain 5Objective 2

Cross Site Request Forgery, Cross Site Scripting and Client Injection Attack GWAPT Practice Questions (Page 9)

Part of the Injection and Client-Side Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 8–14 from this objective — we provide 54 practice questions to prepare you well beyond it. (estimate)

54questions here
11free pages
11concepts

Questions 41–45

  1. 41application · medium

    An online banking application uses a session cookie with no SameSite attribute and has anti-CSRF tokens on all forms. A penetration tester finds that the token is predictable because it is derived from the session ID using a reversible algorithm. Which attack would be most feasible for an attacker to exploit this weakness?

    Select an answer first
  2. 42application · medium

    A tester discovers a stored XSS vulnerability in a forum application. The application uses HttpOnly cookies for session management. Which of the following is the most significant impact the tester can demonstrate?

    Select an answer first
  3. 43foundation · easy

    Which of the following is a common client-side injection variant?

    Select an answer first
  4. 44application · medium

    A web application uses SameSite=Strict cookies to prevent CSRF. However, after deployment, users report that they are logged out when clicking links from external sites, and some legitimate cross-site workflows break. The security team wants to maintain strong CSRF protection while improving usability. Which approach should they implement?

    Select an answer first
  5. 45application · medium

    A web application uses session cookies without the SameSite attribute and relies solely on a hidden anti-CSRF token in forms. During a penetration test, you discover that the token is also exposed in a URL parameter on a page that allows user-generated content. Which additional control would most effectively mitigate CSRF while preserving the application's current functionality?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.