
GIAC Web Application Penetration Tester
Domain 4Objective 1
Web Application Authentication Attacks GWAPT Practice Questions (Page 5)
Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
7concepts
Questions 21–25
- 21
Which flaw in a password reset process allows an attacker to determine whether a given email address is registered?
Select an answer first - 22
A web application has a login form that allows a user to change their password after logging in. The tester notices that the application does not verify the current password before allowing the change. Which attack is most directly enabled?
Select an answer first - 23
A penetration tester is assessing a web application that uses a single sign-on (SSO) protocol. The tester wants to test for authentication bypass. Which of the following is the most effective way to test for SSO authentication bypass?
Select an answer first - 24
A web application uses multi-factor authentication (MFA) where the second factor is a push notification to a mobile app. The application has a 'trust this device' option that sets a cookie. A penetration tester has compromised the user's email account and wants to bypass MFA. Which of the following is the most effective technique?
Select an answer first - 25
Which authentication logic flaw occurs when an application checks a condition (e.g., password) and then performs a state-changing action without re-validating that the condition still holds?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.