
GIAC Web Application Penetration Tester
Domain 4Objective 2
Web Application Session Management GWAPT Practice Questions (Page 5)
Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
9concepts
Questions 21–25
- 21
Which characteristic most directly determines the strength of a session identifier against brute-force guessing?
Select an answer first - 22
A web application is deployed behind a reverse proxy that terminates TLS. The application sets a session cookie without the Secure flag. An attacker on the internal network can sniff traffic between the proxy and the application server. Which of the following is the most effective mitigation?
Select an answer first - 23
Which attack is a common method for session sidejacking?
Select an answer first - 24
Why is it important to clear the session cookie on the client side during logout?
Select an answer first - 25
What should a secure logout mechanism do on the server side?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.