
GIAC Web Application Penetration Tester
Domain 2Objective 1
Reconnaissance and Mapping GWAPT Practice Questions (Page 2)
Part of the Information Gathering and Tooling domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 11–19 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
7concepts
Questions 6–10
- 6
You are mapping the attack surface of a web application that uses both a REST API and a legacy SOAP endpoint. The client wants a comprehensive map but has limited time. Which approach balances thoroughness and efficiency?
Select an answer first - 7
A junior tester is planning the reconnaissance phase for a web application assessment. The tester asks a senior colleague whether to start with passive or active techniques. The client has provided a list of allowed domains but has not yet signed the final authorization for active scanning. Which guidance is most appropriate?
Select an answer first - 8
You are performing active reconnaissance on a web application that has a Web Application Firewall (WAF) that blocks requests containing common SQL injection patterns. You need to enumerate the application's parameters without triggering the WAF. Which approach is most effective?
Select an answer first - 9
Which feature of Burp Suite is most useful for mapping an application's attack surface during reconnaissance?
Select an answer first - 10
Before any active testing, you want to identify the technologies used by a web application using only passive methods. Which source is most likely to reveal the use of a specific JavaScript framework?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.