Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Web Application Penetration Tester

Domain 1Objective 1

Web Application Overview GWAPT Practice Questions (Page 7)

Part of the Web Application Fundamentals domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 8–13 from this objective — we provide 39 practice questions to prepare you well beyond it. (estimate)

39questions here
8free pages
4concepts

Questions 31–35

  1. 31application · medium

    A developer is writing a function that displays a user's first name on a profile page. The name is stored in a database and was originally provided by the user. The developer wants to prevent stored XSS. Which of the following is the most appropriate approach?

    Select an answer first
  2. 32application · medium

    A user reports that after logging into a web application, they can access another user's profile by manually changing the numeric ID in the URL. The application uses session cookies and a REST API. Which HTTP-related control is most directly missing to prevent this unauthorized access?

    Select an answer first
  3. 33application · medium

    A tester is evaluating an application's error handling. The tester sends a request to /product?id=abc and receives a 500 Internal Server Error with a stack trace that includes database connection strings and file paths. Which HTTP status code and information disclosure issue is present?

    Select an answer first
  4. 34foundation · easy

    Which security practice is most directly intended to prevent stored cross-site scripting (XSS) attacks by ensuring that user-supplied data is treated as data rather than executable code when rendered in a web page?

    Select an answer first
  5. 35application · medium

    A penetration tester is assessing a web application that uses a JavaScript single-page application (SPA) front end, a REST API backend, and a PostgreSQL database. During testing, the tester intercepts a request from the browser to the API endpoint /api/users/123 and notices the response includes a custom header X-User-Role: admin. The tester then modifies the request to /api/users/124 and observes that the response contains the user record for user 124. Which architectural component is primarily responsible for enforcing that the tester is authorized to view user 124's data?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.