
GIAC Web Application Penetration Tester
Domain 4Objective 1
Web Application Authentication Attacks GWAPT Practice Questions (Page 4)
Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
7concepts
Questions 16–20
- 16
A web application uses multi-factor authentication (MFA) with a time-based one-time password (TOTP) as the second factor. The application has a 'remember this device' feature that sets a long-lived cookie. A penetration tester has obtained the TOTP secret from a previous test. Which of the following is the most effective way to bypass MFA for a target user?
Select an answer first - 17
A penetration tester is performing a credential stuffing attack against a web application. The application uses a Web Application Firewall (WAF) that blocks requests after 5 failed login attempts from the same IP address. The tester has a list of 10,000 username/password pairs. Which of the following approaches would be most effective in evading the WAF while still testing a large number of credentials?
Select an answer first - 18
What is the primary risk of using a predictable session token generation algorithm?
Select an answer first - 19
A web application allows users to log in with a password and a one-time code sent to their email. A penetration tester discovers that the application does not invalidate the one-time code after a successful login and that the code is valid for 10 minutes. Which attack is most likely to succeed?
Select an answer first - 20
Which of the following is an example of a flawed state transition in an authentication workflow?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.