
GIAC Web Application Penetration Tester
Domain 4Objective 1
Web Application Authentication Attacks GWAPT Practice Questions (Page 2)
Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
7concepts
Questions 6–10
- 6
A web application's password reset process uses a token that is sent to the user's email. The token is a 32-character hexadecimal string. The application stores the token in the database and also sends it in the reset link. A penetration tester has access to the application's database and finds that the token is stored in plaintext. Which of the following is the most significant risk?
Select an answer first - 7
Which attack vector involves an attacker using a list of previously breached username/password pairs to attempt authentication against a web application?
Select an answer first - 8
What is a common weakness of push-notification-based multi-factor authentication that attackers exploit?
Select an answer first - 9
A web application's password reset process asks the user to provide their email address and then sends a reset link. The application responds with 'If that email exists, a reset link has been sent.' However, the response time differs significantly between valid and invalid email addresses. What vulnerability does this indicate?
Select an answer first - 10
A penetration tester is using Burp Suite to test a web application's login functionality. The tester wants to automate a brute-force attack against the password field while keeping the username constant. Which Burp Suite feature is most appropriate for this task?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.