Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Web Application Penetration Tester

Domain 4Objective 2

Web Application Session Management GWAPT Practice Questions (Page 2)

Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
9concepts

Questions 6–10

  1. 6expert · hard

    An online banking application allows users to log in from multiple devices. A user logs in on their desktop and then on their mobile phone. The application currently stores a single session token per user, so logging in on the mobile device invalidates the desktop session. Users are complaining that they are being logged out unexpectedly. The security team wants to maintain the ability to revoke a single device session without affecting others. Which approach should be implemented?

    Select an answer first
  2. 7application · medium

    A web application is deployed behind a load balancer that terminates TLS. The application sets a session cookie without the Secure flag because the connection between the load balancer and the application server is HTTP. A security review flags this as a risk. Which change should be made to ensure the cookie is only sent over HTTPS?

    Select an answer first
  3. 8application · medium

    A development team is designing a new web application and wants to follow OWASP session management best practices. Which combination of controls should be implemented to provide a strong session management foundation?

    Select an answer first
  4. 9expert · hard

    A web application allows users to have multiple concurrent sessions (e.g., on different devices). A security requirement states that a user must be able to revoke a specific session without logging out other sessions. Which of the following is the most appropriate design?

    Select an answer first
  5. 10foundation · easy

    Why is storing a session token in a URL considered insecure?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.