
GIAC Web Application Penetration Tester
Domain 4Objective 1
Web Application Authentication Attacks GWAPT Practice Questions (Page 6)
Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
7concepts
Questions 26–30
- 26
A penetration tester is assessing a web application that uses a JSON-based login API. The tester wants to test for credential stuffing using a large list of breached usernames and passwords. The application returns HTTP 200 with a generic error message for invalid credentials, but returns HTTP 429 after 10 failed attempts from the same IP. Which approach would be most effective for the tester to continue testing without being blocked?
Select an answer first - 27
A penetration tester is analyzing a web application that uses cookies for session management. The tester notices that the session cookie does not have the Secure flag and the application is served over HTTPS. Which attack is most directly enabled?
Select an answer first - 28
What makes a password reset token vulnerable to prediction?
Select an answer first - 29
Which of the following is a common session-based attack vector that targets the session identifier after a user has authenticated?
Select an answer first - 30
A penetration tester is assessing a web application that allows users to log in with email and password. The tester notices that the application does not lock accounts after multiple failed attempts and does not implement any rate limiting on the login endpoint. The tester wants to demonstrate the risk of credential stuffing without causing a denial-of-service condition. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.