
GIAC Web Application Penetration Tester
Domain 3Objective 1
Web Application Configuration Testing GWAPT Practice Questions (Page 8)
Part of the Configuration and Deployment Testing domain, which makes up ~13% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 9–16 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
10concepts
Questions 36–40
- 36
A web application includes a third-party library that is known to be vulnerable. The library is only used on the client side and does not handle sensitive data. The application owner wants to deprioritize the fix. What is the best response from the penetration tester?
Select an answer first - 37
Which of the following is a common insecure default in application frameworks?
Select an answer first - 38
A web application uses a JavaScript library that is three years old and has a known critical vulnerability. The library is loaded from the same origin as the application. What is the most appropriate action for the penetration tester to recommend?
Select an answer first - 39
Which of the following is a common weakness in session management configuration?
Select an answer first - 40
A web server allows the OPTIONS method and responds with 'Allow: GET, HEAD, POST, OPTIONS, TRACE'. A security scanner flags TRACE as a vulnerability. The application team argues that TRACE is needed for debugging. What is the best recommendation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.