
GIAC Web Application Penetration Tester
Domain 3Objective 1
Web Application Configuration Testing GWAPT Practice Questions (Page 7)
Part of the Configuration and Deployment Testing domain, which makes up ~13% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 9–16 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
10concepts
Questions 31–35
- 31
A web server is configured with a strong TLS 1.2 configuration, but it also supports the RC4 cipher suite for legacy clients. A tester wants to recommend disabling RC4. What is the best justification?
Select an answer first - 32
Which of the following is an example of information disclosure through logging?
Select an answer first - 33
A file upload feature accepts any file extension and stores uploads in a directory that is accessible via the web. An attacker uploads a file named shell.php. What is the most likely impact and the best mitigation?
Select an answer first - 34
An application uses a session cookie that is not marked HttpOnly. A tester finds a reflected XSS vulnerability. What is the most likely impact of combining these two issues?
Select an answer first - 35
During testing, you trigger a 404 error and the response includes the internal IP address of the application server. What is the best way to remediate this information disclosure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.