
GIAC Web Application Penetration Tester
Domain 4Objective 1
Web Application Authentication Attacks GWAPT Practice Questions (Page 1)
Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
7concepts
Questions 1–5
- 1
A penetration tester is testing a password reset feature. The application sends a reset link to the user's email, but the link contains a token that is the user's email address encoded in base64. Which flaw is most directly present?
Select an answer first - 2
A web application has a login endpoint that uses a JSON body with 'username' and 'password' fields. The application checks the username and password against a database and then sets a session cookie. A penetration tester finds that if they send a request with a very large password (e.g., 100,000 characters), the application returns a 500 error. Which of the following is the most likely vulnerability?
Select an answer first - 3
A web application uses multi-factor authentication (MFA) where the second factor is a one-time password (OTP) generated by a mobile app. A penetration tester discovers that the OTP verification endpoint does not check whether the OTP has already been used. Which of the following attacks is most directly enabled by this flaw?
Select an answer first - 4
A penetration tester is assessing a web application that uses a single sign-on (SSO) mechanism. The tester wants to test for session-based attacks. Which of the following is the most effective way to test for session fixation?
Select an answer first - 5
Which technique is commonly used to bypass SMS-based multi-factor authentication?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.