
GIAC Web Application Penetration Tester
Domain 5Objective 1
Web Application SQL Injection Attacks GWAPT Practice Questions (Page 2)
Part of the Injection and Client-Side Attacks domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~16–28 in this domain), expect 8–14 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
4concepts
Questions 6–10
- 6
Which manual testing technique involves sending a SQL payload that causes the database to return a different response based on a true or false condition?
Select an answer first - 7
A development team is remediating a SQL injection vulnerability in a legacy application. The application uses dynamic SQL for a search feature and a sort feature. The team has limited time and must prioritize fixes. Which approach best balances security and effort?
Select an answer first - 8
A security architect is reviewing a web application that uses a database account with SELECT, INSERT, UPDATE, and DELETE privileges on all tables. The application uses parameterized queries for all data access. The architect wants to implement defense-in-depth against SQL injection. Which recommendation is most effective?
Select an answer first - 9
Which of the following is the most effective defense against SQL injection?
Select an answer first - 10
A tester has confirmed a UNION-based SQL injection in a MySQL database. The original query returns two columns. The tester wants to extract the database version. Which payload should be used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GWAPT” is a trademark of its owner, used for identification only.