
GIAC Web Application Penetration Tester
Domain 2Objective 1
Reconnaissance and Mapping GWAPT Practice Questions (Page 8)
Part of the Information Gathering and Tooling domain, which makes up ~31% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 11–19 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
7concepts
Questions 36–40
- 36
When performing active reconnaissance, what is a common method to manage the risk of detection?
Select an answer first - 37
A security analyst is performing passive reconnaissance on a target organization before any active testing. The analyst has found the following: WHOIS records show the domain is registered through a privacy service, DNS records include a TXT record with a 'google-site-verification' string, and a search-engine cache shows an old version of the login page with a comment mentioning 'Drupal 8'. Which conclusion is most justified?
Select an answer first - 38
A penetration tester is assigned to assess a web application that is publicly accessible but has a strict rule: no direct interaction with the target until the client approves active testing. The tester needs to build an initial technology profile of the application. Which combination of actions best fits this constraint?
Select an answer first - 39
After discovering several endpoints in a web application, you need to map the attack surface to understand which parameters are submitted via POST requests. Which approach is most efficient?
Select an answer first - 40
Which of the following is an example of an entry point that should be documented when mapping an application's attack surface?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.