Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Web Application Penetration Tester

Domain 3Objective 1

Web Application Configuration Testing GWAPT Practice Questions (Page 3)

Part of the Configuration and Deployment Testing domain, which makes up ~13% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 9–16 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
10concepts

Questions 11–15

  1. 11application · medium

    A penetration tester is asked to perform configuration testing on a web application. The client wants to know if the application is configured securely. Which of the following is the primary goal of configuration testing?

    Select an answer first
  2. 12foundation · easy

    Why is it important to identify outdated third-party components during configuration testing?

    Select an answer first
  3. 13foundation · easy

    In a web application security assessment, what is the primary purpose of configuration testing?

    Select an answer first
  4. 14foundation · easy

    During configuration testing, which of the following is an example of a sensitive file that might be exposed by a web application?

    Select an answer first
  5. 15expert · hard

    You have completed a configuration test and found several issues. The client's development team is resistant to fixing the issues because they believe the findings are not exploitable. What is the most effective way to communicate the findings?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.