Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Web Application Penetration Tester

Domain 1Objective 1

Web Application Overview GWAPT Practice Questions (Page 6)

Part of the Web Application Fundamentals domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 8–13 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
4concepts

Questions 26–30

  1. 26application · medium

    A web application allows users to change their email address. After the change, the application sends a confirmation email to the new address. A tester discovers that the confirmation link does not require authentication and uses a token that is the user's new email address base64-encoded. What is the most likely impact?

    Select an answer first
  2. 27expert · hard

    A web application has a file upload feature that accepts images. The server validates the file's magic bytes and re-encodes the image to strip embedded scripts. However, the application also allows users to download their uploaded files with a user-controlled filename. A tester uploads a benign image and then downloads it with a filename containing a script payload. Which vulnerability is most likely to be exploited?

    Select an answer first
  3. 28foundation · easy

    In a typical three-tier web application architecture, which component is primarily responsible for executing business logic and coordinating requests between the client and the data storage layer?

    Select an answer first
  4. 29application · medium

    A web application uses a login form that submits credentials over HTTPS. After a successful login, the server responds with a 302 redirect to /dashboard and sets a session cookie. The tester notices that the session cookie is not marked with the Secure attribute. Which HTTP-related action should the tester recommend to mitigate the risk of session hijacking?

    Select an answer first
  5. 30foundation · easy

    Which of the following is a primary reason why input validation is considered a critical security control in web applications?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.