Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Web Application Penetration Tester

Domain 1Objective 1

Web Application Overview GWAPT Practice Questions (Page 5)

Part of the Web Application Fundamentals domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 8–13 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
4concepts

Questions 21–25

  1. 21expert · hard

    A company is deploying a web application that uses a content management system (CMS) with a plugin architecture. The CMS runs on a single server with a MySQL database. The security team wants to isolate the CMS from the database to reduce the impact of a SQL injection vulnerability. Which of the following architectural changes would best achieve this?

    Select an answer first
  2. 22application · medium

    A tester is examining an application that uses a REST API. The tester sends a request to /api/items/1 with the header Accept: application/xml and receives an XML response. The tester then sends the same request with Accept: application/json and receives a JSON response. Which HTTP mechanism is the application using to determine the response format?

    Select an answer first
  3. 23application · medium

    A web application uses a REST API that returns JSON responses. A tester sends a request with an 'Accept: application/xml' header and receives an XML response instead of JSON. The tester then submits an XML payload with an external entity reference and receives file contents in the response. Which vulnerability is present?

    Select an answer first
  4. 24application · medium

    A developer is building a search feature that displays user-supplied keywords in the results page. The application currently inserts the keyword directly into the HTML response without any processing. Which secure coding practice should the developer implement to prevent a reflected XSS attack?

    Select an answer first
  5. 25foundation · easy

    Which HTTP request method is defined by the HTTP specification as being intended to retrieve a resource without causing any side effects on the server?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.