
GIAC Web Application Penetration Tester
Domain 5Objective 1
Web Application SQL Injection Attacks GWAPT Practice Questions (Page 1)
Part of the Injection and Client-Side Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 8–14 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
4concepts
Questions 1–5
- 1
A penetration tester is assessing a web application that uses a search feature. The tester submits the string ' OR '1'='1 in the search box and receives a database error revealing the SQL query structure. Which manual detection technique is the tester using, and what is the most likely immediate next step?
Select an answer first - 2
Which manual SQL injection detection technique relies on causing a measurable delay in the database's response to infer information?
Select an answer first - 3
A penetration tester is testing a web application that returns different page content depending on whether a SQL condition is true or false. The tester wants to confirm a SQL injection vulnerability in a numeric parameter. Which manual detection technique should the tester use?
Select an answer first - 4
Which of the following is a common injection point for SQL injection attacks in a web application?
Select an answer first - 5
A development team is fixing a SQL injection vulnerability in a legacy PHP application. The vulnerable code concatenates user input directly into a SQL query. The team wants to implement a defense that is effective and minimizes changes to the existing codebase. Which remediation should the team apply?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.