
GIAC Web Application Penetration Tester
Domain 4Objective 1
Web Application Authentication Attacks GWAPT Practice Questions (Page 8)
Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
7concepts
Questions 36–38
- 36
A penetration tester is examining a password reset feature. The reset link sent to the user's email contains a token that is generated using the current timestamp and the user's email address. The tester notices that the token is predictable. Which attack is most directly enabled by this flaw?
Select an answer first - 37
Which tool is commonly used to automate brute force attacks against web application login forms?
Select an answer first - 38
Which session management vulnerability occurs when an application accepts a session identifier chosen by the attacker and does not generate a new one after authentication?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GWAPT
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.