
GIAC Web Application Penetration Tester
Domain 4Objective 2
Web Application Session Management GWAPT Practice Questions (Page 3)
Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
9concepts
Questions 11–15
- 11
Which method is the most secure way to transmit a session token?
Select an answer first - 12
When a user opens multiple tabs in the same browser, what is a common session management approach?
Select an answer first - 13
A security review of a web application reveals that session IDs are generated using a predictable sequence (e.g., incrementing integers). Which of the following is the most appropriate remediation?
Select an answer first - 14
Which defense is most effective against session fixation?
Select an answer first - 15
A security engineer is evaluating a session ID generation algorithm. The algorithm produces a 128-bit value using a cryptographically secure PRNG, but the application truncates the value to 32 bits before using it as the session ID. Which statement best describes the security impact?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.