Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Web Application Penetration Tester

Domain 4Objective 2

Web Application Session Management GWAPT Practice Questions (Page 7)

Part of the Authentication and Session Management domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
9concepts

Questions 31–35

  1. 31expert · hard

    A web application's logout function clears the session cookie on the client but does not invalidate the session on the server. A penetration tester notes that the session can be replayed after logout. Which of the following is the most complete remediation?

    Select an answer first
  2. 32foundation · easy

    Which standard or guideline provides comprehensive best practices for session management?

    Select an answer first
  3. 33foundation · easy

    Which of the following is a core component of session management?

    Select an answer first
  4. 34application · medium

    A developer is reviewing the session management of a web application that handles financial transactions. The current session ID is a 32-character hexadecimal string generated using the application server's default PRNG, which has been shown to have a predictable pattern under load. The application also sends the session ID in a URL parameter when cookies are disabled. The security team requires that session IDs be resistant to prediction and that they not be exposed in URLs. Which combination of changes should the developer implement?

    Select an answer first
  5. 35application · medium

    A financial application requires users to re-authenticate after 10 minutes of inactivity, but also forces a full logout after 8 hours regardless of activity. A security auditor notes that the absolute timeout is too long for high-risk transactions. Which change best aligns with OWASP guidance while minimizing user friction?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.